Hi,

   ** Downref: Normative reference to an Historic RFC: RFC 6587

Kent: hmmm, what's going on here?  This YANG module is providing an ability to configure 
the "tcp" transport, even though the IESG made that ability historic in 2012 
(see IESG Note below).  Searching online, it looks like Cisco supports this, but Juniper 
does not.  What about other vendors, is it widely supported?  Was this discussed in the 
WG?  Answering my own question, searching my local mailbox, I don't see this ever being 
discussed before, other than Martin questioning if it was a good idea in Mar 2016 (no 
response).  Please start a thread on the list to get WG opinion if it's okay for the 
draft to proceed as is or not.  Here's the IESG Note from RFC 6587:

    IESG Note

    The IESG does not recommend implementing or deploying syslog over
    plain tcp, which is described in this document, because it lacks the
    ability to enable strong security [RFC3365].

    Implementation of the TLS transport [RFC5425] is recommended so that
    appropriate security features are available to operators who want to
    deploy secure syslog.  Similarly, those security features can be
    turned off for those who do not want them.



Well, I believe it's clear plain TCP should not be in the YANG module.

Regards, Benoit

_______________________________________________
netmod mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/netmod

Reply via email to