Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?

Michael Thomas <[email protected]>
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
Randy Presuhn writes:
 > Hi -
 > 
 > > From: Michael Thomas <[email protected]>
 > > Message-ID: <[email protected]>
 > > Date: Mon, 9 Dec 2002 17:08:25 -0800 (PST)
 > > To: Wes Hardaker <[email protected]>
 > > Cc: Michael Thomas <[email protected]>, [email protected],
 > >         "Harrington, David" <[email protected]>,
 > >         "Chris Elliott" <[email protected]>,
 > >         "Wijnen, Bert (Bert)" <[email protected]>,
 > >         "[email protected] (E-mail)" <[email protected]>
 > > Subject: Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?
 > > In-Reply-To: <[email protected]>
 > > References: <6D745637A7E0F94DA070743C55CDA9BA256F06@NHROCMBX1.ets.enterasys.com>
 > > 	<[email protected]>
 > > 	<[email protected]>
 > > 	<[email protected]>
 > ...
 > >    I'm not saying that IPsec would be a good fit;
 > >    quite the opposite, actually. I'm arguing that app
 > >    layer security without key management is, well,
 > >    useless was the first thing that popped into my
 > >    mind, but I should probably be more charitable.
 > >    It really makes deciding what to do at any sort
 > >    of scale *very* hard given the inferior choices.
 > > 
 > >    As I said, for MIDCOM this is a very distinct
 > >    negative for SNMPv3 as a choice, all other
 > >    things being equal. Any other wg considering 
 > >    SNMPv3 as the basis for their protocol would be
 > >    well advised to take that into consideration.
 > ...
 > 
 > Could you give an example of a protocol in use that does
 > initial key distribution, key update, authentication and access
 > control management well?  (All four, not just one or two.)
 > With SNMPv3 USM+VACM, we get three out of the four.  If there
 > were a good way to get all four, I think the WG would like
 > to know about it.

Irrelevant, but IKE,KINK/IPsec and TLS fit your
definition. This working group decided for its
own reasons that app layer auth/priv/authz was
required. As such, none of the usual suspects can
be used for key management for those SA. We are
left with a void. This manifestly causes trouble
with generally poorly conceived and reviewed
stopgaps.

Trying to say that the world is an imperfect place
therefore lets bury our head in the sand is a huge
cop out. In the context of MIDCOM, SNMPv3 should
be dismissed out of hand because it doesn't have
key management. It's that serious.

		Mike
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.