RE: [midcom] SNMPv3 as MIDCOM protocol: Opinions?

Chris Elliott <[email protected]>
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
On Fri, 6 Dec 2002, Michael Thomas wrote:

>
> I think you can factor out crypto of any stripe
> because it's a requirement regardless of which
> layer you implement it at.

I disagree--there are many applications for SNMP where encryption isn't
required. I don't think we'll see general use of encryption for every
frame inside Enterprise networks for many years. Authentication is just
catching on there and I belive that most Enterprises will be quite happy,
and rightly so, with just strong authentication for SNMP.

>
> That said: assuming the number of round trips is
> identical for SNMP vs other contenders, this "too
> expensive" argument strikes me as yet another
> rehash of the ASN.1/ABNF crusades. Is it that time
> of year again?

Agreed. If this argument had won with the xwindows developers at MIT it
clearly would never have been developed. I think the hurdle implementers
see with SNMPv3 exists for AuthNoPriv and AuthPriv almost equally and has
much more to do with user/key management than the "cost" of the protocol.

I think that making v3 easier to deploy for large environments by
supporting external authentication servers (Radius/Kerberos/Diameter/etc.)
would go far toward convincing implementers to deploy it.

Chris.

>
> 	Mike

Chris Elliott  CCIE# 2013       |         |
Customer Diagnostic Engineer   |||       |||
RTP, NC, USA                  |||||     |||||
919-392-2146              .:|||||||||:|||||||||:.
[email protected]        c i s c o S y s t e m s
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.