Hi,
** Downref: Normative reference to an Historic RFC: RFC 6587
Kent: hmmm, what's going on here? This YANG module is providing an ability to configure
the "tcp" transport, even though the IESG made that ability historic in 2012
(see IESG Note below). Searching online, it looks like Cisco supports this, but Juniper
does not. What about other vendors, is it widely supported? Was this discussed in the
WG? Answering my own question, searching my local mailbox, I don't see this ever being
discussed before, other than Martin questioning if it was a good idea in Mar 2016 (no
response). Please start a thread on the list to get WG opinion if it's okay for the
draft to proceed as is or not. Here's the IESG Note from RFC 6587:
IESG Note
The IESG does not recommend implementing or deploying syslog over
plain tcp, which is described in this document, because it lacks the
ability to enable strong security [RFC3365].
Implementation of the TLS transport [RFC5425] is recommended so that
appropriate security features are available to operators who want to
deploy secure syslog. Similarly, those security features can be
turned off for those who do not want them.
Well, I believe it's clear plain TCP should not be in the YANG module.
Regards, Benoit
_______________________________________________
netmod mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/netmod