Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?

Michael Thomas <[email protected]>
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
Wes Hardaker writes:
 > >>>>> On Mon, 9 Dec 2002 16:32:28 -0800 (PST), Michael Thomas <[email protected]> said:
 > 
 > Michael> I'd frankly recommend that they not use v3 USM features at
 > Michael> all and rely on IPsec instead.
 > 
 > You really need app to app security for decent access control to
 > objects like the ones that the SNMP provides.  IPsec will not cut it
 > at all here, IMHO.

   I'm not saying that IPsec would be a good fit;
   quite the opposite, actually. I'm arguing that app
   layer security without key management is, well,
   useless was the first thing that popped into my
   mind, but I should probably be more charitable.
   It really makes deciding what to do at any sort
   of scale *very* hard given the inferior choices.

   As I said, for MIDCOM this is a very distinct
   negative for SNMPv3 as a choice, all other
   things being equal. Any other wg considering 
   SNMPv3 as the basis for their protocol would be
   well advised to take that into consideration.

        Mike
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.