[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: Final pass on BOF issues for -01



> If a vendor adds ssh to their product, I would be happy to see them
> disable/remove telnet at the same time.
> Agreed?

Yes, but that's more of a "how should the knobs be set" question.
This doc is dealing more with "what knobs shold be there".

See:

   2.5.1   Ability to Identify All Listening Services . . . . . . . . 17
   2.5.2   Ability to Disable Any and All Services  . . . . . . . . . 17


2.12.8 Ability to Authenticate Without Reusable Plaintext Passwords

   Requirement. The device MUST perform authentication without the
      transmission of reusable plain-text passwords across a network.

---George