Re: I-D ACTION:draft-hardaker-snmp-session-sm-00.txt

"Randy Presuhn" <[email protected]> Tue, 14 Oct 2003 09:01:03 -0700
Newsgroups gmane.ietf.snmpv3
Message-ID <002f01c3926c$5e6e0e20$7f1afea9@oemcomputer>
Hi -

> From: "Sharon Chisholm" <[email protected]>
> To: <[email protected]>
> Cc: "Wes Hardaker" <[email protected]>
> Sent: Tuesday, October 14, 2003 6:08 AM
> Subject: RE: I-D ACTION:draft-hardaker-snmp-session-sm-00.txt
...
> Might I suggest then that providing a MIB way of doing the same thing might
> just be noise? As for more detailed configuration, why can't this be done in
> the protocol? A monitoring MIB would be useful though if you can keep it
> nice and simple - i.e. no superfluous configuration.
...

I agree that *superluous* configuration should be avoided, but I think that
some very basic configuration / control capabilities are essential, such as
permitting a security administrator to kill a session in progress (getting back
to the issues Gene originally raised much earlier in this thread).

As to the basic question "why can't this be done in the protocol", I think
the answer centers around the question of *who* should have the
rights to do such configuration.  My intuition is that it would normally be
a security administrator, rather than the session user, who would set
things up, kill sessions, and so on.  If this is correct, then building it
into the protocol would not make sense, since the wrong user would
be behind the protocol operations requesting the configuration change.

Randy