[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

FW: Internal WG Review: Recharter of Security Issues in Network E vent Logging (syslog)



Another MIB doctor comment/question:

-----Original Message-----
From: C. M. Heard [mailto:heard@pobox.com]
Sent: Wednesday, January 04, 2006 15:22
To: Wijnen, Bert (Bert)
Cc: Mreview (E-mail)
Subject: Re: Internal WG Review: Recharter of Security Issues in Network
Event Logging (syslog) 


On Wed, 4 Jan 2006, Wijnen, Bert (Bert) wrote:
> This is still in internal IESG/IAB review. But if any of you has
> early comments, pls do send them asap (before Thursday 11am
> EST).

One minor comment:  the first paragraph of the proposed charter
says:

> Syslog is a de-facto standard for logging system events.  
> However, the protocol component of this event logging system has
> not been formally documented.  While the protocol has been very
> useful and scalable, it has some known security problems which
> were documented in RFC 3164.

I am somewhat confused by the statements "the protocol component of
this event logging system has not been formally documented."  I
thought RFC 3164, whose title is "The BSD syslog Protocol" did
exactly that.  I suspect that others may be confused too.

//cmh