[netmod] Roman Danyliw's Discuss on draft-ietf-netmod-factory-default-14: (with DISCUSS and COMMENT)
Roman Danyliw via Datatracker <noreply@ietf.org> Tue, 21 April 2020 12:51 UTC
Return-Path: <noreply@ietf.org>
X-Original-To: netmod@ietf.org
Delivered-To: netmod@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 842E93A0B81; Tue, 21 Apr 2020 05:51:42 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Roman Danyliw via Datatracker <noreply@ietf.org>
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-netmod-factory-default@ietf.org, netmod-chairs@ietf.org, netmod@ietf.org, Kent Watsen <kent+ietf@watsen.net>, kent+ietf@watsen.net
X-Test-IDTracker: no
X-IETF-IDTracker: 6.127.0
Auto-Submitted: auto-generated
Precedence: bulk
Reply-To: Roman Danyliw <rdd@cert.org>
Message-ID: <158747350209.22509.2374705458402957087@ietfa.amsl.com>
Date: Tue, 21 Apr 2020 05:51:42 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/74FBlhaEyzCx-VA8DGp1fjwdR7w>
Subject: [netmod] Roman Danyliw's Discuss on draft-ietf-netmod-factory-default-14: (with DISCUSS and COMMENT)
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.29
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Apr 2020 12:51:43 -0000
Roman Danyliw has entered the following ballot position for draft-ietf-netmod-factory-default-14: Discuss When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html for more information about IESG DISCUSS and COMMENT positions. The document, along with other ballot positions, can be found here: https://datatracker.ietf.org/doc/draft-ietf-netmod-factory-default/ ---------------------------------------------------------------------- DISCUSS: ---------------------------------------------------------------------- Please use YANG security considerations template from https://trac.ietf.org/trac/ops/wiki/yang-security-guidelines. Specifically (as a DISCUSS item): ** (Per the template questions “for all YANG modules you must evaluate whether any readable data”) Would factory-default contain any sensitive information in certain network environments where the ACLs should be more restrictive that world readable for everyone? Per “The operational disruption caused by setting the config to factory default contents varies greatly depending on the implementation and current config”, it seems like it could be worse than just an operational disruption. Please note that a default configuration could be insecure or not have security controls enabled whereby exposing the network to compromise. ---------------------------------------------------------------------- COMMENT: ---------------------------------------------------------------------- Please use YANG security considerations template from https://trac.ietf.org/trac/ops/wiki/yang-security-guidelines. Specifically (as a COMMENT item): ** Add “The Network Configuration Access Control Model (NACM) [RFC8341] provides the means to …”
- [netmod] Roman Danyliw's Discuss on draft-ietf-ne… Roman Danyliw via Datatracker
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Qin Wu
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Kent Watsen
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Andy Bierman
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Qin Wu
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Rob Wilton (rwilton)
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Kent Watsen
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Rob Wilton (rwilton)
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Juergen Schoenwaelder
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Andy Bierman
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Qin Wu
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Qin Wu
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Roman Danyliw
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Qin Wu
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Rob Wilton (rwilton)
- Re: [netmod] Roman Danyliw's Discuss on draft-iet… Qin Wu