RE: [midcom] SNMPv3 as MIDCOM protocol: Opinions?

"Harrington, David" <[email protected]>
Newsgroups gmane.ietf.snmpv3
Message-ID <6D745637A7E0F94DA070743C55CDA9BA256F06@NHROCMBX1.ets.enterasys.com>
Hi,

SNMPv3 has RFC2786 "Diffie-Hellman USM Key MIB" to automate key distribution. This approach has been in use in DOCSIS environments for a while now. I wouldn't call that nothing.

dbh

> -----Original Message-----
> From: Michael Thomas [mailto:[email protected]]
> Sent: Saturday, December 07, 2002 2:47 PM
> To: Chris Elliott
> Cc: Michael Thomas; Wijnen, Bert (Bert); Harrington, David;
> [email protected] (E-mail)
> Subject: RE: [midcom] SNMPv3 as MIDCOM protocol: Opinions?
> 
> 
> Chris Elliott writes:
>  > On Fri, 6 Dec 2002, Michael Thomas wrote:
>  > > I think you can factor out crypto of any stripe
>  > > because it's a requirement regardless of which
>  > > layer you implement it at.
>  > 
>  > I disagree--there are many applications for SNMP where 
> encryption isn't
>  > required. I don't think we'll see general use of 
> encryption for every
>  > frame inside Enterprise networks for many years. 
> Authentication is just
>  > catching on there and I belive that most Enterprises will 
> be quite happy,
>  > and rightly so, with just strong authentication for SNMP.
> 
> We're talking about Midcom specifically here. I
> assume that the Midcom requirements will have at
> the very least auth/authz and probably
> confidentiality requirements. As such, it doesn't
> really make a huge difference when you talk about
> performance whether its done at app layer ala
> SNMPv3 or transport/network as TLS/IPsec.
> 
>  > I think that making v3 easier to deploy for large environments by
>  > supporting external authentication servers 
> (Radius/Kerberos/Diameter/etc.)
>  > would go far toward convincing implementers to deploy it.
> 
> This is actually a distinct negative for SNMPv3:
> complete abdication of the problem of key
> distribution. With COPS and MEGACO you get TLS
> and/or IKE/KINK. SNMPv3 has nothing. For Midcom,
> I'd think this is a significant problem.
> 
> 	    Mike
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.