RE: [Isms] Why SNMPv3? [WG Review: Integrated Security Model forSNMP(isms)]

"David B Harrington" <[email protected]> Mon, 27 Sep 2004 19:53:23 -0400
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
Hi EricF,

operationally insecure? I hadn't heard this concern. Can you
elaborate? 

dbh 

-----Original Message-----
From: [email protected] [mailto:[email protected]]
On Behalf Of Fleischman, Eric
Sent: Monday, September 27, 2004 6:06 PM
To: EricLKlein; [email protected]; [email protected]
Subject: RE: [Isms] Why SNMPv3? [WG Review: Integrated Security Model
forSNMP(isms)]

However, some of those of us who want to use SNMPv3 USM have found it
to be operationally insecure and would like to have an approach for
SNMP that leverages existing key distribution systems (e.g., PKI,
Kerberos, etc.) already deployed within our infrastructures.

-----Original Message-----
From: EricLKlein [mailto:[email protected]]
Sent: Friday, September 24, 2004 8:24 AM
To: [email protected]; [email protected]
Subject: Re: [Isms] Why SNMPv3? [WG Review: Integrated Security Model
for SNMP(isms)]


I tend to agree with Chris, many service providers are starting to
wake up to the lack of security in SNMP I and II, and have started
requiring compliance in the NMS / OSS products that they want.

SNMP III is the best solution for this so far and is important.

Eric
----- Original Message -----
From: "Chris Elliott" <[email protected]>
To: "Wes Hardaker" <[email protected]>
Cc: "Thomas D. Nadeau" <[email protected]>;
<[email protected]>; <[email protected]>
Sent: 24 September, 2004 6:54 AM
Subject: Re: [Isms] Why SNMPv3? [WG Review: Integrated Security Model
for SNMP (isms)]


> We (Cisco Systems) sell, mostly to enterprises, a network management
> system (CiscoWorks) that requires SNMP write access for much of it's
> functionality and I have personally worked with many Fortune 100
companies
> that are using this NMS and allowing SNMP write access to their
network
> devices, along with countless smaller companies.
>
> We also sell a large number of DOCSIS-compliant devices. DOCSIS
requires
> SNMP write access for configuration and provisioning.
>
> We sell other network management systems into the service provider
market
> that require SNMP write access to the managed devices. They continue
to
> sell and be used.
>
> SNMP, with write access, is in use today in many environments. These
> customers typically are using this write access with insecure
community
> strings and are securing access with access lists and private
management
> networks.
>
> I believe that the advantages of using a secure protocol, such as
SNMPv3,
> along with the ability to authenticate against existing user
databases,
> will be easier to deploy and more secure than the existing methods.
>
> Chris.
>
> On Thu, 23 Sep 2004, Wes Hardaker wrote:
>
> > >>>>> On Thu, 23 Sep 2004 15:28:41 -0400, "Thomas D. Nadeau"
<[email protected]> said:
> >
> > Thomas> Being a reality and actually being used are two different
things.
> > Thomas> I too have developed numerous modules that are writable,
but not
many
> > Thomas> people use them.
> >
> > I sure get an awful lot of questions about an operation that
> > supposedly isn't used.
> >
> > [note the recent ISMS survey results (see the proceedings) had
about
> > 1/5th of the responses saying they used SNMP for configuration]
> >
> > --
> > Wes Hardaker
> > Sparta
> >
> > _______________________________________________
> > Isms mailing list
> > [email protected]
> > https://www1.ietf.org/mailman/listinfo/isms
> >
>
> Chris Elliott  CCIE# 2013       |         |
> Customer Diagnostic Engineer   |||       |||
> RTP, NC, USA                  |||||     |||||
> 919-392-2146              .:|||||||||:|||||||||:.
> [email protected]        c i s c o S y s t e m s



_______________________________________________
Isms mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/isms