Re: [OPSAWG] Implementation of RFC7630

joel jaeggli <joelja@bogus.com> Sun, 22 November 2015 20:45 UTC

Return-Path: <joelja@bogus.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 097701B34C0 for <opsawg@ietfa.amsl.com>; Sun, 22 Nov 2015 12:45:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.485
X-Spam-Level:
X-Spam-Status: No, score=-2.485 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.585] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ULpRMc85a09Z for <opsawg@ietfa.amsl.com>; Sun, 22 Nov 2015 12:45:08 -0800 (PST)
Received: from nagasaki.bogus.com (nagasaki.bogus.com [IPv6:2001:418:1::81]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C2C6A1B34BF for <opsawg@ietf.org>; Sun, 22 Nov 2015 12:45:08 -0800 (PST)
Received: from mb-2.local ([IPv6:2601:1c0:c102:22fb:dcd6:8d20:dc38:5fb4]) (authenticated bits=0) by nagasaki.bogus.com (8.14.9/8.14.9) with ESMTP id tAMKj5BU073170 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Sun, 22 Nov 2015 20:45:06 GMT (envelope-from joelja@bogus.com)
To: Joe Clarke <jclarke@cisco.com>, "opsawg@ietf.org" <opsawg@ietf.org>
References: <565219EC.1080007@cisco.com>
From: joel jaeggli <joelja@bogus.com>
X-Enigmail-Draft-Status: N1110
Message-ID: <56522951.8010807@bogus.com>
Date: Sun, 22 Nov 2015 12:45:05 -0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:42.0) Gecko/20100101 Thunderbird/42.0
MIME-Version: 1.0
In-Reply-To: <565219EC.1080007@cisco.com>
Content-Type: multipart/signed; micalg="pgp-sha1"; protocol="application/pgp-signature"; boundary="6a1mLgXKcaHBm7X6L1beXD3iVpjmnD4Gk"
Archived-At: <http://mailarchive.ietf.org/arch/msg/opsawg/Yxlw-fHjYG6AeXHjVoJrrps61-4>
Subject: Re: [OPSAWG] Implementation of RFC7630
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 22 Nov 2015 20:45:10 -0000

On 11/22/15 11:39 AM, Joe Clarke wrote:
> I was getting some questions from internal parties regarding the
> implementation of SHA-2 authn for SNMPv3, and wanted to check the list
> to gage what NMS vendors and operators might be considering with respect
> to this.  Is there a strong desire among operators to move to adopt
> SHA-2?  Are those operators already using SNMPv3 or would this provide
> the necessary push to move to v3?  Are there NMS applications already
> adopting SHA-2?  Thanks.

We use SHA and AES with snmp v3. Given the general pressue other parts
of the business to carefully track and generally improve which crypto
suites are used we would probably move there if the hardware supported
it (I don't think getting it done in the NMS would really be that hard).
To the extent that I had an auditor ask about it, it's been a while, but
md5 and des was the topic of conversation at that time.

> Joe
> 
> _______________________________________________
> OPSAWG mailing list
> OPSAWG@ietf.org
> https://www.ietf.org/mailman/listinfo/opsawg
>