Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?

"Steven M. Bellovin" <[email protected]>
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
In message <[email protected]>, Michael Thomas wri
tes:
>Wes Hardaker writes:
> > >>>>> On Mon, 9 Dec 2002 16:32:28 -0800 (PST), Michael Thomas <[email protected]
>m> said:
> > 
> > Michael> I'd frankly recommend that they not use v3 USM features at
> > Michael> all and rely on IPsec instead.
> > 
> > You really need app to app security for decent access control to
> > objects like the ones that the SNMP provides.  IPsec will not cut it
> > at all here, IMHO.
>
>   I'm not saying that IPsec would be a good fit;
>   quite the opposite, actually. I'm arguing that app
>   layer security without key management is, well,
>   useless was the first thing that popped into my
>   mind, but I should probably be more charitable.
>   It really makes deciding what to do at any sort
>   of scale *very* hard given the inferior choices.


What Mike said.

		--Steve Bellovin, http://www.research.att.com/~smb (me)
		http://www.wilyhacker.com ("Firewalls" book)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.