Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?
Randy Presuhn <[email protected]>
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Message-ID | <[email protected]> |
Hi - > From: Michael Thomas <[email protected]> > Message-ID: <[email protected]> > Date: Tue, 10 Dec 2002 08:16:07 -0800 (PST) > To: Randy Presuhn <[email protected]> > Cc: [email protected] > Subject: Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions? > In-Reply-To: <[email protected]> > References: <[email protected]> ... > > Could you give an example of a protocol in use that does > > initial key distribution, key update, authentication and access > > control management well? (All four, not just one or two.) > > With SNMPv3 USM+VACM, we get three out of the four. If there > > were a good way to get all four, I think the WG would like > > to know about it. > > Irrelevant, but IKE,KINK/IPsec and TLS fit your > definition. This working group decided for its > own reasons that app layer auth/priv/authz was > required. As such, none of the usual suspects can > be used for key management for those SA. We are > left with a void. This manifestly causes trouble > with generally poorly conceived and reviewed > stopgaps. ... I guess I'm being unusually dense today. Could you explain how the IKE,KINK/IPsec and TLS combination delivers the initial authentication material ("who is superuser and how do I recognize them") to a virgin box in a wiring closet somewhere? This is the only part of SNMPv3 key management that is not addressed by the SNMPv3 protocol and MIBs. (I'd also be curious to learn how the IKE/KINK/IPsec/TLS combination addresses the question of access control management. It might be obvious to you, but I don't see it yet.) ------------------------------------------------------ Randy Presuhn BMC Software, Inc. SJC-1.3141 [email protected] 2141 North First Street Tel: +1 408 546-1006 San José, California 95131 USA ------------------------------------------------------ My opinions and BMC's are independent variables. ------------------------------------------------------