Re: [Netconf] draft-ietf-netconf-monitoring-09 last call comments from js
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Netconf] draft-ietf-netconf-monitoring-09 last call comments from js



Juergen Schoenwaelder writes:
>Not sure I understand your comment - why does radius/tacplus lead to a
>difference between a "user name" and a "login name"? Which AVPs are
>you referring to?

AVP?  My comment has that with radius I can login as one user and
have the radius server return a different user name to use locally,
so I can remotely administer a hundred operators as a single
"operator" local user.  So the permissions may track with the real
user name ("operator") but the login name ("phil") is also vital
information.

>This is pretty much what we have been doing in SMIv2 land.

Cool.  I've seen examples that aren't this way, where the
MIB text documents the leafs, but not their meaning.  An
example would be rfc3412, where in a ~40 page rfc, the mib
is ~3 pages.

Thanks,
 Phil

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.