A long-standing operational issue with the security added to SNMPv3 is the fact that it does not integrate with existing security infrastructures, i.e., password and account databases. Although SNMPv3 was the first SNMP version that added security to the protocol, there have been reservations about deploying it because it's "yet another user database to maintain." The author (and others) are looking into creating an add-on security extention to the SNMPv3 protocol that will better integrate with your existing security infrastructure.
In this presentation, the author will be soliciting feedback about whether this work is important to the operational community and which security infrastructures are most important to target (RADIUS, local accounts, X.509 certificates, SSH, Kerberos, etc). The feedback obtained from the operational community will directly impact whether the work progresses and what requirements it must fulfill to be considered complete - we appreciate your input!
About the Presenter
Wes Hardaker is a Senior Research Scientist working for Sparta, Inc.
His work focuses on network security research and secure network
management. Wes's currently focuses on managing security policy
within large complex networks implementing policies that are
enforced using IPsec security services. He is the lead developer of
the Net-SNMP open source network management package, as well as
multiple other open source network management packages.
Wes is also actively involved within the IETF and is
helping define new security and network management protocols and
standards.
PDF presentation
RealVideo stream