Re: NETCONF over TLS?

Andy Bierman <ietf@andybierman.com> Thu, 30 March 2006 17:04 UTC

Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1FP0Zv-00066k-7D for netconf-archive@lists.ietf.org; Thu, 30 Mar 2006 12:04:59 -0500
Received: from psg.com ([147.28.0.62]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1FP0Zu-0006GS-UN for netconf-archive@lists.ietf.org; Thu, 30 Mar 2006 12:04:59 -0500
Received: from majordom by psg.com with local (Exim 4.60 (FreeBSD)) (envelope-from <owner-netconf@ops.ietf.org>) id 1FP0Wi-0009uV-Bu for netconf-data@psg.com; Thu, 30 Mar 2006 17:01:40 +0000
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on psg.com
X-Spam-Level:
X-Spam-Status: No, score=-2.5 required=5.0 tests=AWL,BAYES_00, FORGED_RCVD_HELO autolearn=ham version=3.1.1
Received: from [205.178.146.54] (helo=ns-omrbm4.netsolmail.com) by psg.com with esmtp (Exim 4.60 (FreeBSD)) (envelope-from <ietf@andybierman.com>) id 1FP0Wf-0009u6-Ry for netconf@ops.ietf.org; Thu, 30 Mar 2006 17:01:38 +0000
Received: from mail.networksolutionsemail.com (omr4.mgt.bos.netsol.com [10.49.2.114] (may be forged)) by ns-omrbm4.netsolmail.com (8.12.10/8.12.10) with SMTP id k2UH1ZQ3002424 for <netconf@ops.ietf.org>; Thu, 30 Mar 2006 12:01:35 -0500
Received: (qmail 2927 invoked by uid 78); 30 Mar 2006 17:01:35 -0000
Received: from unknown (HELO ?192.168.0.12?) (andy@andybierman.com@24.24.133.237) by 10.49.34.114 with SMTP; 30 Mar 2006 17:01:35 -0000
Message-ID: <442C0EE8.3020204@andybierman.com>
Date: Thu, 30 Mar 2006 09:01:28 -0800
From: Andy Bierman <ietf@andybierman.com>
User-Agent: Thunderbird 1.5 (Windows/20051201)
MIME-Version: 1.0
To: Eliot Lear <lear@cisco.com>
CC: "Netconf (E-mail)" <netconf@ops.ietf.org>
Subject: Re: NETCONF over TLS?
References: <442C0D9E.3070401@andybierman.com> <442C0E16.3010608@cisco.com>
In-Reply-To: <442C0E16.3010608@cisco.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Sender: owner-netconf@ops.ietf.org
Precedence: bulk
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 50a516d93fd399dc60588708fd9a3002

Eliot Lear wrote:
> There's no reason you couldn't do this with TLS/BEEP, right?

Right.
So we already have this covered, except you
have to implement BEEP.  I think that was
the point of the original question.  Like I said,
just curious -- not trying to create new work at all.


> 
> Eliot

Andy

> 
> Andy Bierman wrote:
>> Hi,
>>
>> Somebody sent me an email and asked if the WG was
>> interested in NETCONF over TLS.  I said probably
>> not.  This morning I saw this I-D in Last Call
>> to supply a user name to TLS, an obvious missing
>> component is you want to support a user-based
>> access-control model (and I do).
>>
>> http://www.ietf.org/internet-drafts/draft-santesson-tls-ume-04.txt
>>
>> So now I am curious (but not enough to standardize
>> anything) if the secure syslog integration with netconf
>> over TLS makes security and operational sense.
>>
>>
>> Andy
>>
>>
>> -- 
>> to unsubscribe send a message to netconf-request@ops.ietf.org with
>> the word 'unsubscribe' in a single line as the message text body.
>> archive: <http://ops.ietf.org/lists/netconf/>
>>
> 
> 


--
to unsubscribe send a message to netconf-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/netconf/>