[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [spam score 5/10 -pobox] draft-jones-opsec-01.txt comments

 "gj" == George Jones <gmj@pobox.com> writes:

>> I suspect we want to require that there always be a way to get full
>> access to change the configuration on the device on the OOB
>> management port without rebooting it, and without the device
>> consulting any other devices to determine authentication.

gj> without rebooting ?

Do you mean something similar to configuring RADIUS for normal usage
(including OOB serial console), but with a fallback to some fixed
local authenticator in case of RADIUS failure?

Or do you mean ability to do password recovery without rebooting?

I'd agree with the first, disagree with the second.

I think it should be "MUST be possible to configure", not "MUST be
possible".  I can see environments where fixed local authenticators
are less desireable than access when the AAA protocol is down.
