Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?

Randy Presuhn <[email protected]>
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
Hi -

> From: Michael Thomas <[email protected]>
> Message-ID: <[email protected]>
> Date: Tue, 10 Dec 2002 08:16:07 -0800 (PST)
> To: Randy Presuhn <[email protected]>
> Cc: [email protected]
> Subject: Re: [midcom] SNMPv3 as MIDCOM protocol: Opinions?
> In-Reply-To: <[email protected]>
> References: <[email protected]>
...
>  > Could you give an example of a protocol in use that does
>  > initial key distribution, key update, authentication and access
>  > control management well?  (All four, not just one or two.)
>  > With SNMPv3 USM+VACM, we get three out of the four.  If there
>  > were a good way to get all four, I think the WG would like
>  > to know about it.
> 
> Irrelevant, but IKE,KINK/IPsec and TLS fit your
> definition. This working group decided for its
> own reasons that app layer auth/priv/authz was
> required. As such, none of the usual suspects can
> be used for key management for those SA. We are
> left with a void. This manifestly causes trouble
> with generally poorly conceived and reviewed
> stopgaps.
...

I guess I'm being unusually dense today.  Could you explain how
the IKE,KINK/IPsec and TLS combination delivers the initial
authentication material ("who is superuser and how do I
recognize them") to a virgin box in a wiring closet somewhere?

This is the only part of SNMPv3 key management that is not
addressed by the SNMPv3 protocol and MIBs.

(I'd also be curious to learn how the IKE/KINK/IPsec/TLS
combination addresses the question of access control
management.  It might be obvious to you, but I don't see
it yet.)

 ------------------------------------------------------
 Randy Presuhn          BMC Software, Inc.  SJC-1.3141
 [email protected]  2141 North First Street
 Tel: +1 408 546-1006   San José, California 95131  USA
 ------------------------------------------------------
 My opinions and BMC's are independent variables.
 ------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.