Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?
Michael Thomas <[email protected]>
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Message-ID | <[email protected]> |
Wes Hardaker writes: > >>>>> On Mon, 9 Dec 2002 16:32:28 -0800 (PST), Michael Thomas <[email protected]> said: > > Michael> I'd frankly recommend that they not use v3 USM features at > Michael> all and rely on IPsec instead. > > You really need app to app security for decent access control to > objects like the ones that the SNMP provides. IPsec will not cut it > at all here, IMHO. I'm not saying that IPsec would be a good fit; quite the opposite, actually. I'm arguing that app layer security without key management is, well, useless was the first thing that popped into my mind, but I should probably be more charitable. It really makes deciding what to do at any sort of scale *very* hard given the inferior choices. As I said, for MIDCOM this is a very distinct negative for SNMPv3 as a choice, all other things being equal. Any other wg considering SNMPv3 as the basis for their protocol would be well advised to take that into consideration. Mike