Re: [Isms] open issues
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Isms] open issues



Hi -

> From: "David Harrington" <ietfdbh at comcast.net>
> To: "'Randy Presuhn'" <randy_presuhn at mindspring.com>; <isms at ietf.org>
> Sent: Wednesday, April 30, 2008 10:26 AM
> Subject: RE: [Isms] open issues
>

> The securityName represents the principal on whose behalf the
> notification was originated. So typically, this is not the host, but
> the identity of the "user" on whose behalf the notification is sent.
> 
> **on whose behalf** was an important phrase during SNMNPv3
> development.
...

Yes.  And in the case of the notification originator, it isn't necessarily
the same string as the securityName used by the subscriber, even
though that's probably the most common case.  (The reason for
making it different is if one is extremely paranoid about the possibility
of compromised systems being used to generate phony notification
streams puporting to come from some other system.)  But even in that
case, this other securityName is still conceptually used to identify (as an
alias, if you will) the user on whose behalf the information is being sent.

Randy

_______________________________________________
Isms mailing list
Isms at ietf.org
https://www.ietf.org/mailman/listinfo/isms



Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.