Issue: missing enumeration for 'sftp' and 'scp' as managed protocols
"Sanchez, Mauricio (PNB Roseville)" <mauricio.sanchez@hp.com> Wed, 09 March 2005 22:50 UTC
Envelope-to: radiusext-data@psg.com
Delivery-date: Wed, 09 Mar 2005 22:51:47 +0000
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C524FA.777EA5E6"
Subject: Issue: missing enumeration for 'sftp' and 'scp' as managed protocols
Date: Wed, 09 Mar 2005 14:50:59 -0800
Message-ID: <D6D515539AD08046B7E6A4C02E72623E021B16D0@cacexc08.americas.cpqcorp.net>
Thread-Topic: Issue: missing enumeration for 'sftp' and 'scp' as managed protocols
Thread-Index: AcUk+naAgZHRsqMyTeir4A9RD2NtjA==
From: "Sanchez, Mauricio (PNB Roseville)" <mauricio.sanchez@hp.com>
To: radiusext@ops.ietf.org
Issue: SFTP and SCP has been left out as explicit managed administrative protocols. Submitter name: Mauricio Sanchez Submitter email address: mauricio.sanchez@hp.com Date first submitted: 5/9/2005 Reference: Document: draft-nelson-radius-management-authorization-01.txt Comment type: T Priority: S Section: 8.1, 8.2 Rationale/Explanation of issue: see below Length description of problem SFTP and SCP should be treated seperately from SSH-based console access. SFTP and SCP are SSH-based file transfer services and should not implicity be lumped with console based access. Requested change: Suggest that a new values (4) and (5) be allocated under the 'Framed-Management-Protocol' (section 8.1) or the 'Non-Framed-Managed-Protocol' (section 8.2) attribute for SFTP and SCP protocols, respectively. It's not clear to me whether SCP and SFTP should be considered a framed or non-framed protocol. Moreover, draft should elaborate on the explicit meaning of SSH being used in only a console access role for administrative purposes (which is it's nominal role anyway). -------------------------------------------- Mauricio Sanchez, CISSP Network Security Architect Procurve Networking Business Hewlett Packard 8000 Foothills Boulevard, ms 5555 Roseville CA, 95747-5557 916.785.1910 Tel 916.785.1815 Fax mauricio.sanchez@hp.com --------------------------------------------
- Issue: missing enumeration for 'sftp' and 'scp' a… Sanchez, Mauricio (PNB Roseville)