Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?
Matjaz Vrecko <[email protected]>
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Organization | MG-SOFT Corp. |
| Message-ID | <[email protected]> |
Wes Hardaker wrote: >>This is actually a distinct negative for SNMPv3: complete abdication >>of the problem of key distribution. With COPS and MEGACO you get TLS >>and/or IKE/KINK. SNMPv3 has nothing. For Midcom, I'd think this is a >>significant problem. > > > FYI, there is also a kerberos SNMP draft (2 actually) and an > implementation of it in the Net-SNMP toolkit. The IESG are not > allowing these IDs (or any other security models) to be considered for > the standards track at this time, however. There have been many other > discussions surrounding other session-based security models, but no > IDs have been written for them yet. MG-SOFT has already published products that include SNMPv3 engine with full Diffie-Hellman USM support, that David mentioned earlier today. And anytime soon now we will also come out with products with Kerberos USM extesnion, that Wes mentioned in his response. Best regards, Matjaz -- Matjaz Vrecko MG-SOFT Corporation, Strma ulica 8, SI-2000 Maribor, Slovenia Internet: http://www.mg-soft.si/ E-mail: <[email protected]> Phone: +386 2 2506565, Fax: +386 2 2506566