Re: [netmod] Secdir last call review of draft-ietf-netmod-syslog-model-21

2018-02-23 Thread Kent Watsen
> Security Comments > > * I think almost all writable data nodes here are sensitive, because a network > attacker's first move is to block any logging on the host, and many of the data > nodes here can be used for this purpose. > > [clw1] I

Re: [netmod] Secdir last call review of draft-ietf-netmod-syslog-model-21

2018-02-21 Thread Gary Wu (garywu)
> Security Comments > > * I think almost all writable data nodes here are sensitive, because a network > attacker's first move is to block any logging on the host, and many of the data > nodes here can be used for this purpose. > > [clw1] I w

Re: [netmod] Secdir last call review of draft-ietf-netmod-syslog-model-21

2018-02-19 Thread Yaron Sheffer
Hi Clyde, Thank you for responding to my comments. I am OK with all of your responses. Best, Yaron On 19/02/18 13:02, Clyde Wildes (cwildes) wrote: Yaron, Thanks for your review. My answers are inline as [clw1]. On 2/18/18, 6:31 AM, "Yaron Sheffer" wrote: Reviewer: Yaron Sheff

Re: [netmod] Secdir last call review of draft-ietf-netmod-syslog-model-21

2018-02-19 Thread Clyde Wildes (cwildes)
Yaron, Thanks for your review. My answers are inline as [clw1]. On 2/18/18, 6:31 AM, "Yaron Sheffer" wrote: Reviewer: Yaron Sheffer Review result: Has Issues General Comments * The semantics of pattern matching is not clear: "and/or the message text" - are there c

[netmod] Secdir last call review of draft-ietf-netmod-syslog-model-21

2018-02-18 Thread Yaron Sheffer
Reviewer: Yaron Sheffer Review result: Has Issues General Comments * The semantics of pattern matching is not clear: "and/or the message text" - are there cases where you only match the text but not the facility/severity? * It's very confusing to specify rollover in minutes, but retention in hour