[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: additional comments about draft-ietf-netconf-tls-00.txt



On Jan 28, 2008 7:34 PM, Eliot Lear <lear@cisco.com> wrote:
Mohamad Badra wrote:
>> Can someone please explain to me how NETCONF/TLS could be used in
>> combination with existing user authentication databases on NETCONF
>> servers (e.g., the agents)?
>
> Before answer your question, I will appreciate if you could kindly
> tell me how HTTP/TLS, "LDAP protocol over TLS/SSL", FTP/TLS and other
> protocols do that?
>
> Best regards,

HTTP/TLS uses HTTP AUTH to accomplish this task.  I don't know much
about LDAP, but I suspect there's a SASL or SASL-like transaction
somewhere in there.  FTP uses the same username/password approaches that
existed before TLS.  My point: there is no such underlying mechanism in
NETCONF.
 
This is not directly specified in the document since it relies on Requirements for Management Interfaces specified in rfc4279. However, if you think it should be clarified, please suggest some text!
 
Best regards,
--
Badra