[netmod] YANG module security considerations

Ladislav Lhotka <lhotka@nic.cz> Fri, 01 December 2017 12:13 UTC

Return-Path: <lhotka@nic.cz>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6F3A01271DF for <netmod@ietfa.amsl.com>; Fri, 1 Dec 2017 04:13:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7
X-Spam-Level:
X-Spam-Status: No, score=-7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nic.cz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RWqEP69116MY for <netmod@ietfa.amsl.com>; Fri, 1 Dec 2017 04:13:04 -0800 (PST)
Received: from mail.nic.cz (mail.nic.cz [IPv6:2001:1488:800:400::400]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4F791126579 for <netmod@ietf.org>; Fri, 1 Dec 2017 04:13:04 -0800 (PST)
Received: from birdie (unknown [IPv6:2001:718:1a02:1::380]) by mail.nic.cz (Postfix) with ESMTPSA id 9DA4B6451D for <netmod@ietf.org>; Fri, 1 Dec 2017 13:13:02 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=nic.cz; s=default; t=1512130382; bh=EplGiTTFVbWrHzU29DWtn34K9yTwkojnz8GndBjGbT0=; h=From:To:Date; b=c1tv0DTAjzaxmdFEmDq8tmRH1dYad1BZ7J+bHVGbv5bEY/g6fPxgoCtewjydVdHxW W8r9iJ3WGV8h4ZxPZbteH8PVI24DDIunLiBkJ5D8qUUVRCCrlDbTPyvbPYTfMLME2h DlRk4Tqd4ANXCgO6tk0co2F3IAxqzakjUl0PdiIo=
Message-ID: <1512130382.9397.20.camel@nic.cz>
From: Ladislav Lhotka <lhotka@nic.cz>
To: NETMOD WG <netmod@ietf.org>
Date: Fri, 01 Dec 2017 13:13:02 +0100
Organization: CZ.NIC
Content-Type: text/plain; charset="UTF-8"
X-Mailer: Evolution 3.26.2
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: clamav-milter 0.99.2 at mail
X-Virus-Status: Clean
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/vht3x-kF8Yfp2qiN9PtHKWp3unk>
Subject: [netmod] YANG module security considerations
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 Dec 2017 12:13:06 -0000

Hi,

the security considerations template text [1] that has already been used in a
number of documents is apparently incorrect - YANG modules aren't accessed by NM
protocols. Hence

OLD

The YANG module defined in this document is designed to be accessed via network
management protocols such as ...

NEW

The YANG module specified in this document defines a schema for data that is
designed to be accessed via network management protocols such as ...


[1] https://trac.ietf.org/trac/ops/wiki/yang-security-guidelines

Lada

-- 
Ladislav Lhotka
Head, CZ.NIC Labs
PGP Key ID: 0xB8F92B08A9F76C67