Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?

Michael Thomas <[email protected]>
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
Wes Hardaker writes:
 > FYI, there is also a kerberos SNMP draft (2 actually) and an
 > implementation of it in the Net-SNMP toolkit.  The IESG are not
 > allowing these IDs (or any other security models) to be considered for
 > the standards track at this time, however.  There have been many other
 > discussions surrounding other session-based security models, but no
 > IDs have been written for them yet.

I resemeble one of those drafts :) Frankly, I
think the IESG ought to lay down a policy which
says that anything which defines application layer
security associations MUST specify a key
management protocol to key those security
associations. I don't think this is entirely
different from what Steve Bellovin wrote in his
-use-ipsec-00 draft (one of its cruxes was "if you
can use a previously defined key management
protocol, you are strongly recommended to do so."

The proof is in the pudding: the lack of SNMPv3
keying has lead to not one, but *two* different
key distribution mechanisms by Cablelabs alone,
not to mention Ken's Kerberos mechanism too.
$DEITY knows how many other -- probably poorly
thought out -- other ones lurk out there. As I
said, this is a major weakness of SNMPv3 when
being used as a general purpose frob as is being
proposed by folks in MIDCOM. I'd frankly recommend
that they not use v3 USM features at all and rely
on IPsec instead.

	 Mike
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.