Re: [netmod] I-D Action: draft-ietf-netmod-factory-default-04.txt

Qin Wu <bill.wu@huawei.com> Tue, 05 November 2019 08:21 UTC

Return-Path: <bill.wu@huawei.com>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE6B1120152 for <netmod@ietfa.amsl.com>; Tue, 5 Nov 2019 00:21:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3hwpCYcCPtOi for <netmod@ietfa.amsl.com>; Tue, 5 Nov 2019 00:21:50 -0800 (PST)
Received: from huawei.com (lhrrgout.huawei.com [185.176.76.210]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9B1261200F9 for <netmod@ietf.org>; Tue, 5 Nov 2019 00:21:50 -0800 (PST)
Received: from lhreml708-cah.china.huawei.com (unknown [172.18.7.108]) by Forcepoint Email with ESMTP id 2C64ECCA61B514F5E0AA; Tue, 5 Nov 2019 08:21:49 +0000 (GMT)
Received: from lhreml710-chm.china.huawei.com (10.201.108.61) by lhreml708-cah.china.huawei.com (10.201.108.49) with Microsoft SMTP Server (TLS) id 14.3.408.0; Tue, 5 Nov 2019 08:21:47 +0000
Received: from lhreml710-chm.china.huawei.com (10.201.108.61) by lhreml710-chm.china.huawei.com (10.201.108.61) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.1713.5; Tue, 5 Nov 2019 08:21:47 +0000
Received: from DGGEML422-HUB.china.huawei.com (10.1.199.39) by lhreml710-chm.china.huawei.com (10.201.108.61) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.1.1713.5 via Frontend Transport; Tue, 5 Nov 2019 08:21:47 +0000
Received: from DGGEML531-MBS.china.huawei.com ([169.254.5.209]) by dggeml422-hub.china.huawei.com ([10.1.199.39]) with mapi id 14.03.0439.000; Tue, 5 Nov 2019 16:21:17 +0800
From: Qin Wu <bill.wu@huawei.com>
To: "Schönwälder, Jürgen" <J.Schoenwaelder@jacobs-university.de>, john heasley <heas@shrubbery.net>
CC: "netmod@ietf.org" <netmod@ietf.org>
Thread-Topic: [netmod] I-D Action: draft-ietf-netmod-factory-default-04.txt
Thread-Index: AdWTsai+A2ywY/DzRGesOBsBhvj2rA==
Date: Tue, 05 Nov 2019 08:21:17 +0000
Message-ID: <B8F9A780D330094D99AF023C5877DABAA93E9947@dggeml531-mbs.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.134.31.203]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/Hi6Y0vdsThFIbAVqu79SLVku7do>
Subject: Re: [netmod] I-D Action: draft-ietf-netmod-factory-default-04.txt
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Nov 2019 08:21:53 -0000

Thanks Jurgen and John, the proposed change works for me.

-Qin
-----邮件原件-----
发件人: netmod [mailto:netmod-bounces@ietf.org] 代表 Sch?nw?lder, Jürgen
发送时间: 2019年11月5日 15:47
收件人: john heasley <heas@shrubbery.net>
抄送: netmod@ietf.org
主题: Re: [netmod] I-D Action: draft-ietf-netmod-factory-default-04.txt

On Tue, Nov 05, 2019 at 07:42:06AM +0000, john heasley wrote:
>    In addition,the "factory-reset" RPC might also be used
>    to trigger some other restoring and resetting tasks such as files
>    cleanup, restarting the node or some of the software processes,
>    setting some security data/passwords to the default value, removing
>    logs, or removing any temporary data (from datastore or elsewhere),
>    etc.
> 
> It seems that this should all be part of this draft.  An operation 
> that wipes a device for decommission is useful.  Whether it is a home 
> or commercial device.

Yes to your point.

But every time I read the phrase "setting some security data/passwords to the default value" I am feeling uneasy. The notion of 'default passwords' is scary and a knob to restore default passwords even more so. Perhaps the text should say instead 'removing security credentials and restoring default security settings'.

/js

-- 
Juergen Schoenwaelder           Jacobs University Bremen gGmbH
Phone: +49 421 200 3587         Campus Ring 1 | 28759 Bremen | Germany
Fax:   +49 421 200 3103         <https://www.jacobs-university.de/>

_______________________________________________
netmod mailing list
netmod@ietf.org
https://www.ietf.org/mailman/listinfo/netmod