Re: [Netconf] notification access control
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Netconf] notification access control



Randy Presuhn wrote:
Hi -


Here is a use-case example of what I mean.

Let's say a WG or vendor defines a config-change
notification that includes a 'username' field
(i.e., who made the config change).

Let's say an operator using equipment purchased
from the vendor decides to implement a security policy
that usernames are restricted data (because they aid
brute-force login attacks which guess usernames).

Should NETCONF be flexible enough to allow the operator
to decide security policy, not the WG or equipment vendor?

IMO, yes.  IMO, SNMP made a big assumption by deciding
that any access-control filtering applied on the payload means
the payload will be unusable by the manager.  NETCONF should
not make the same mistake.


Randy


Andy





Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.