security considerations in raqmon-pdu

"Romascanu, Dan \(Dan\)" <[email protected]> Tue, 28 Feb 2006 08:07:58 +0200
Newsgroups gmane.ietf.rmonmib
Message-ID <AAB4B3D3CF0F454F98272CBE187FDE2F0A1AAE10@is0004avexu1.global.avaya.com>
The editorial team of raqmon-pdu met yesterday with the Security (Sam
Hartman) and OAM (Bert Wijnen) ADs to discuss the solution for the
pending DISCUSS introduced by Sam Hartman during the IESG discussion on
raqmon concerning the need to specify how to use TLS with raqmon for the
RDS-RRC interaction. 
 
The proposed solution is to run a SASL plain authentication session in
the layer beyond the raqmon PDU, so that explicit acks and nacks are
being returned by the RRC without the need to create new PDU types or
modify the unidirectional architecture of the raqmon PDUs. Examples for
such a solution can be found in section 4 of RFC 3080 and section 6 of
RFC 3920.
 
The editors will add to the Security Considerations section of the
raqmon-pdu document text that describes this solution. The solution will
be run for verification with the ADs and with experts from the TLS WG,
and submitted in a revision of the raqmon-pdu draft before the next week
cut-off submission date for the Internet-Drafts.   
 
Regards,
 
Dan

_______________________________________________
RMONMIB mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/rmonmib