• Revised I-D Needed - Issue raised by WG
  • Awaiting Expert Review/Resolution of Issues Raised
  • Awaiting External Review/Resolution of Issues Raised
  • Awaiting Merge with Other Document
  • Author or Editor Needed
  • Waiting for Referenced Document
  • Waiting for Referencing Document
  • Revised I-D Needed - Issue raised by WGLC
  • Revised I-D Needed - Issue raised by AD
  • Revised I-D Needed - Issue raised by IESG
  • Doc Shepherd Follow-up Underway
  • Other - see Comment Log

IETF :: manet

Current state: WG Consensus: Waiting for Write-Up

Viewing the last 20 entries. Show full log.

Barry Leiba

[Ballot Position Update] New position, No Objection, has been recorded for Barry Leiba

Benoit Claise

Telechat date has been changed to 2013-05-30 from 2013-05-16

Benoit Claise

State changed to IESG Evaluation - Defer from IESG Evaluation

Sean Turner

[Ballot comment]
Thanks for being so quick to resolve my discuss.

Sean Turner

[Ballot Position Update] Position for Sean Turner has been changed to No Objection from Discuss

Sean Turner

[Ballot discuss]
Revised (I think this might just be a ctrl-x/ctrl-v issue but was asked to provide a little more rationale on my discuss)

The 2nd to last paragraph in this document:

It is RECOMMENDED that implementers consider the security
features as provided by the SNMPv3 framework (see [RFC3410],
Section 8, including full support for the SNMPv3
cryptographic mechanisms (for authentication and privacy).

differs somewhat from what I thought was last agreed with the MIB doctors (and what's in RFC 6779):

Implementations SHOULD provide the security features
described by the SNMPv3 framework (see [RFC3410]),
and implementations claiming compliance to the SNMPv3
standard MUST include full support for authentication
and privacy via the User-based Security Model (USM)
[RFC3414] with the AES cipher algorithm [RFC3826].
Implementations MAY also provide support for the
Transport Security Model (TSM) [RFC5591] in combination
with a secure transport such as SSH [RFC5592] or TLS/DTLS
[RFC6353].

My primary issue here is that a requirement to "consider" is not the same an MTI (mandatory to implement). Further, the RFC 3414 mechanisms referred to in RFC 3410 for authentication are HMAC-based and for privacy are CBC-DES-based. Don't really have a problem with the authentication protocols (see RFC 6151 and 6194) but I do have a really big problem with the CBC-DES-based privacy mechanism. The reworded boiler plate takes in to account the AES-based privacy mechanism RFC 3414 refers to as a draft. I can not believe you'd really use a DES-based mechanism instead of the AES-based mechanism and if you are I'd like to see some text about that.

The bit about the TSM is a nod to reality about how the data will be gathered. I'm guessing here but I suspect that SSH is used with the router so you could just say SSH is required as opposed to the current wishy washy one or the approach in the new boiler plate.

Sean Turner

Ballot discuss text updated for Sean Turner

Ulrich Herberg

IANA Review state changed to Version Changed - Review Needed from IANA OK - Actions Needed

Ulrich Herberg

New revision available

Sean Turner

[Ballot discuss]
Any reason this one doesn't have the boilerplate:
https://svn.tools.ietf.org/area/ops/trac/wiki/mib-security
Isn't the 2nd to last paragraph missing for the security considerations?

Sean Turner

[Ballot Position Update] New position, Discuss, has been recorded for Sean Turner

Stewart Bryant

[Ballot Position Update] New position, No Objection, has been recorded for Stewart Bryant

Brian Haberman

[Ballot Position Update] New position, No Objection, has been recorded for Brian Haberman

Martin Stiemerling

[Ballot Position Update] New position, No Objection, has been recorded for Martin Stiemerling

Joel Jaeggli

[Ballot Position Update] New position, No Objection, has been recorded for Joel Jaeggli

(System)

IANA Review state changed to IANA OK - Actions Needed from IANA - Review Needed

Adrian Farrel

State changed to IESG Evaluation from Waiting for AD Go-Ahead::AD Followup

Adrian Farrel

Placed on agenda for telechat - 2013-05-16

Adrian Farrel

Changed consensus to Yes from Unknown

Adrian Farrel

Ballot has been issued

Viewing the last 20 entries. Show full log.