Re: [Isms] Comments on the BTSMS proposal
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Isms] Comments on the BTSMS proposal
On Wed, Aug 03, 2005 at 09:37:28PM +0200, Tom Petch wrote:
> The only minor point I would like to add to is about including the
> actual security level in the information passed to the engine. I
> have no problem with the requested security level being handled as
> it is. I cannot currently produce a compelling reason why we need
> the actual security level when we are using SSH security at the
> transport layer but have a nagging feeling we will, perhaps for
> security audits, logs, exploitation by the engine itself (eg it
> knows it has priv and so can afford to send information it otherwise
> would not),.... so I would rather see it passed betwen transport and
> engine if it reasonably can, rather than find out later it is needed
> and we don't have it.
If you read the TLSM draft, you will see that this information is
supposed to be passed via a cache reference between the transport
layer security portion and the SNMP layer security portion. Dave
Perkins suggested to support a MIB module which allows you to retrieve
information about the session details, which might be useful (if alone
for debugging purposes).
> If those on this list with a security background say that knowing
> the actual security level used (authentication, encryption,
> integrity - not the particular algorithm) in a data transfer is not
> needed for security purposes, I would feel reassured (ie would shut
> up about it). eg if a security breach is detected, does it matter
> that we do not know at the application level whether the message was
> encrypted or not?
As said above, the TLSM draft passes this information up to the
security model portion of the SSH security model where a check can be
made whether the actual security level matches the required security
level.
/js
--
Juergen Schoenwaelder International University Bremen
<http://www.eecs.iu-bremen.de/> P.O. Box 750 561, 28725 Bremen, Germany
_______________________________________________
Isms mailing list
Isms at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/isms
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.