Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?
"Steven M. Bellovin" <[email protected]>
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Message-ID | <[email protected]> |
In message <[email protected]>, Michael Thomas wri tes: >Wes Hardaker writes: > > >>>>> On Mon, 9 Dec 2002 16:32:28 -0800 (PST), Michael Thomas <[email protected] >m> said: > > > > Michael> I'd frankly recommend that they not use v3 USM features at > > Michael> all and rely on IPsec instead. > > > > You really need app to app security for decent access control to > > objects like the ones that the SNMP provides. IPsec will not cut it > > at all here, IMHO. > > I'm not saying that IPsec would be a good fit; > quite the opposite, actually. I'm arguing that app > layer security without key management is, well, > useless was the first thing that popped into my > mind, but I should probably be more charitable. > It really makes deciding what to do at any sort > of scale *very* hard given the inferior choices. What Mike said. --Steve Bellovin, http://www.research.att.com/~smb (me) http://www.wilyhacker.com ("Firewalls" book)