Re: [sacm] minor comments on draft-lin-sacm-nid-mp-security-baseline-03
Adam Montville <adam.w.montville@gmail.com> Mon, 23 July 2018 20:28 UTC
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 88901130E25 for <sacm@ietfa.amsl.com>; Mon, 23 Jul 2018 13:28:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XdsqoZtqRakf for <sacm@ietfa.amsl.com>; Mon, 23 Jul 2018 13:28:34 -0700 (PDT)
Received: from mail-oi0-x231.google.com (mail-oi0-x231.google.com [IPv6:2607:f8b0:4003:c06::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3C59C130F29 for <sacm@ietf.org>; Mon, 23 Jul 2018 13:28:34 -0700 (PDT)
Received: by mail-oi0-x231.google.com with SMTP id n84-v6so3508412oib.9 for <sacm@ietf.org>; Mon, 23 Jul 2018 13:28:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=xIAmXmwO31ip9endC052J8CmjoNzRjXsckgIcDro5A0=; b=kIrXx90BpeYpdsBP/bAEI6bTfDFYcjkL4MAE8eTA0gAENwmMoqPIgnBB7vz6IL5y5r myGUT1KKSytgIQ75asaC5k/zolI0GOjsx/YpG/k3THYyYMYG5BuE3kAerFVcs/luAALs MVbM0DSfxGrbtVdKUTgTh9np94UkftrAGDkHJ1OryenHKiIBOXEWmYBVpOZi5KPZ01+k jzdY/3RrTAH8/yMd2+u+HBcK3cMlh5/7XdL9hYM+lVY1uaa6XOTyLQoNEMJOaWZ8J+sp uH5lveLRO+PvZ2PnD0IfrW5LAXAk6+mhhOfGtXAL3MvEkBFLj/BCnnNHWfbET3eUbUXO /SWQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=xIAmXmwO31ip9endC052J8CmjoNzRjXsckgIcDro5A0=; b=VstOMng0rVOFcrZdHbyt4qk2gQg5XCQF/2U6YQ4yDw96W1Ah/Nozhdc4GoyrmhiCrp jpL3jTwhz8SyXeAEk8jSYlfDqvJVwC8QCHc3CbbmwktHSPkrPdjgLebP4c2EvmohgQKw 71LdRpsiut9pK3Avdo8T26KusJCmRhifWVeq0kF5wstpSc1lUdAZ+jcPz2mJlAK+fQ3O RTzSCgWmXfh2Hgd7ic3uD1zyJtGPokN+CNX4UPAjIxaubW8H+mbsYwot8QByBb9qNLd2 Qv4DgAH+Oiq5XvveF+4261ShJIHtmdcAAeAYhvARwhNjQ1n84pDH3859O6VC/AY6VsRc AsVw==
X-Gm-Message-State: AOUpUlFEaOi6X/vzlRhO2uSfMtblr8m6G+AWk7KUxda5PVKGf9HE3cnd /UVO9YDXc6kaZqaqscPST2E=
X-Google-Smtp-Source: AAOMgpdfxo+xblZTLQICp1yh0axPaIhO3ZVQyWsXI+UV8bwGyRAb/D4ufyBUkCbpPaGX5Hna5OWgwg==
X-Received: by 2002:aca:4914:: with SMTP id w20-v6mr313316oia.5.1532377713355; Mon, 23 Jul 2018 13:28:33 -0700 (PDT)
Received: from austinfventures.lan (99-64-100-131.lightspeed.austtx.sbcglobal.net. [99.64.100.131]) by smtp.gmail.com with ESMTPSA id y85-v6sm10639166oie.25.2018.07.23.13.28.31 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 23 Jul 2018 13:28:32 -0700 (PDT)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
From: Adam Montville <adam.w.montville@gmail.com>
In-Reply-To: <20180723180058.GX92448@kduck.kaduk.org>
Date: Mon, 23 Jul 2018 15:28:30 -0500
Cc: sacm@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <9483592D-A262-451D-9016-35C134AFBB97@gmail.com>
References: <20180723180058.GX92448@kduck.kaduk.org>
To: Benjamin Kaduk <kaduk@mit.edu>
X-Mailer: Apple Mail (2.3445.9.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/kKspdlxIYF7x1STI5HWApa_MffQ>
Subject: Re: [sacm] minor comments on draft-lin-sacm-nid-mp-security-baseline-03
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jul 2018 20:28:37 -0000
Two good points, Ben. I have two comments inline. I think I mentioned this at the mic, during the SACM session, but I'm interested in whether anyone else sees value in defining a "baseline registry" over draft-based baselines (I'm still not sure that baseline is the right label for these, but I'm going with it until I think of something better). For example, a year from now those password complexity settings may be something the world wants to remove from the baseline... I wouldn't want to need to reopen the draft. I'd prefer to update a registry somewhere. This may be less of an issue (but not a non-issue) for network devices, and it's certainly an issue for operating systems, applications, cloud environments, and probably IoT. If folks think this is a sane idea, I'd volunteer to create such a draft. Kind regards, Adam > On Jul 23, 2018, at 1:01 PM, Benjamin Kaduk <kaduk@mit.edu> wrote: > > During Jessica's talk I noticed a couple things I wanted to mention, but > that didn't seem to merit getting up to the mic: > > There's a container for 'telnet' admin access; my understanding is that > there are not any applications out there that could be called "telnet" and > are actually secure these days (but maybe I'm missing some!); e.g., > kerberized telnet mostly only uses single-DES and a lousy cipher mode, with > a vendor-specific option for triple-DES, which is deprecated as of my > document that's currently at the RFC Editor. So we may want to have some > text clarifying the situation and disrecommending its use (or even remove > it entirely, if that's feasible). FWIW, I don't believe there's a single recent CIS Benchmark (security configuration guide) that doesn't recommend disabling telnet entirely. > > Similarly, there's a pwd-sec-policy container that describes password > security policies. While it's definitely true that password policies and > mandatory change intervals are currently widely deployed, it's less clear > whether their usage should still be considered useful or a best current > practice -- I think I've seen some research go by that suggests that not > requiring character classes or frequency of change can be just as secure > (and, of course, if passwords can be avoided entirely that can also help). > So, perhaps there is room for some qualifying text here as well. Qualifying text is a good idea. There are usually caveats accompanying more modern guidance (i.e. MFA or use of loooong passwords). At CIS, we've had a hard time reconciling both worlds while we're in a transition. There is still a large group of folks out there who find comfort in the complexity constraints and don't have faith in users to rely on long pass phrases, etc. > > -Ben > (with no hats) > > _______________________________________________ > sacm mailing list > sacm@ietf.org > https://www.ietf.org/mailman/listinfo/sacm
- [sacm] minor comments on draft-lin-sacm-nid-mp-se… Benjamin Kaduk
- Re: [sacm] minor comments on draft-lin-sacm-nid-m… Adam Montville
- Re: [sacm] minor comments on draft-lin-sacm-nid-m… Benjamin Kaduk
- Re: [sacm] minor comments on draft-lin-sacm-nid-m… Jarrett Lu
- Re: [sacm] minor comments on draft-lin-sacm-nid-m… Linqiushi (Jessica, CSPL)
- Re: [sacm] minor comments on draft-lin-sacm-nid-m… Sherif Mansour
- Re: [sacm] minor comments on draft-lin-sacm-nid-m… Adam Montville
- Re: [sacm] minor comments on draft-lin-sacm-nid-m… Benjamin Kaduk
- [sacm] 答复: minor comments on draft-lin-sacm-nid-m… Xialiang (Frank, Network Integration Technology Research Dept)
- Re: [sacm] 答复: minor comments on draft-lin-sacm-n… Adam Montville
- Re: [sacm] 答复: minor comments on draft-lin-sacm-n… Sherif Mansour
- Re: [sacm] minor comments on draft-lin-sacm-nid-m… Adam Montville
- Re: [sacm] minor comments on draft-lin-sacm-nid-m… Sherif Mansour
- Re: [sacm] 答复: minor comments on draft-lin-sacm-n… Benjamin Kaduk
- Re: [sacm] minor comments on draft-lin-sacm-nid-m… Adam Montville
- [sacm] 答复: minor comments on draft-lin-sacm-nid-m… Xialiang (Frank, Network Integration Technology Research Dept)
- Re: [sacm] 答复: minor comments on draft-lin-sacm-n… Henk Birkholz
- [sacm] Pro/Con WRT To Registry (WAS: Re: minor co… Adam Montville
- [sacm] Terminology: Baseline Data Model (WAS: Re:… Adam Montville