Re: [Netconf] notification access control
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Netconf] notification access control
Randy Presuhn wrote:
Hi -
Here is a use-case example of what I mean.
Let's say a WG or vendor defines a config-change
notification that includes a 'username' field
(i.e., who made the config change).
Let's say an operator using equipment purchased
from the vendor decides to implement a security policy
that usernames are restricted data (because they aid
brute-force login attacks which guess usernames).
Should NETCONF be flexible enough to allow the operator
to decide security policy, not the WG or equipment vendor?
IMO, yes. IMO, SNMP made a big assumption by deciding
that any access-control filtering applied on the payload means
the payload will be unusable by the manager. NETCONF should
not make the same mistake.
Randy
Andy
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.