Network Working Group F. Kastenholz
Request for Comments: 1472 FTP Software, Inc.
June 1993
The Definitions of Managed Objects for the Security Protocols of the Point-to-Point Protocol
1. The Network Management Framework
The Internet-standard Network Management Framework consists of three components. They are:
Kastenholz [Page 1]
RFC 1472 PPP/Security MIB June 1993
STD 17/RFC 1213 which defines MIB-II, the core set of managed objects for the Internet suite of protocols.
2. Objects
Managed objects are accessed via a virtual information store, termed the Management Information Base or MIB. Objects in the MIB are defined using the subset of Abstract Syntax Notation One (ASN.1) [3] defined in the SMI. In particular, each object type is named by an OBJECT IDENTIFIER, an administratively assigned name. The object type together with an object instance serves to uniquely identify a specific instantiation of the object. For human convenience, we often use a textual string, termed the descriptor, to refer to the object type.
2.1. Format of Definitions
Section 4 contains the specification of all object types contained in this MIB module. The object types are defined using the conventions defined in the SMI, as amended by the extensions specified in [5,6].3. Overview 3.1. Object Selection CriteriaTo be consistent with IAB directives and good engineering practice, an explicit attempt was made to keep this MIB as simple as possible. This was accomplished by applying the following criteria to objects proposed for inclusion:
Kastenholz [Page 2]
RFC 1472 PPP/Security MIB June 1993 3.2. Structure of the PPPThis section describes the basic model of PPP used in developing the PPP MIB. This information should be useful to the implementor in understanding some of the basic design decisions of the MIB.
3.3. MIB Groups
Objects in this MIB are arranged into several MIB groups. Each group is organized as a set of related objects.
Kastenholz [Page 3]
RFC 1472 PPP/Security MIB June 1993
This document specifies the following group:
4. Definitions
PPP-SEC-MIB DEFINITIONS ::= BEGIN
Kastenholz [Page 4]
RFC 1472 PPP/Security MIB June 1993
-- PPP Security Group -- Implementation of this group is optional.
Kastenholz [Page 5]
RFC 1472 PPP/Security MIB June 1993
::= { pppSecurityConfigEntry 1 }
Kastenholz [Page 6]
RFC 1472 PPP/Security MIB June 1993
-- This table contains all of the ID/Secret pair information.
Kastenholz [Page 7]
RFC 1472 PPP/Security MIB June 1993
PppSecuritySecretsEntry ::= SEQUENCE {
Kastenholz [Page 8]
RFC 1472 PPP/Security MIB June 1993
::= { pppSecuritySecretsEntry 3 }
Kastenholz [Page 9]
RFC 1472 PPP/Security MIB June 1993
::= { pppSecuritySecretsEntry 6 }
5. Acknowledgements
This document was produced by the PPP working group. In addition to the working group, the author wishes to thank the following individuals for their comments and contributions:
Kastenholz [Page 10]
RFC 1472 PPP/Security MIB June 1993 6. Security ConsiderationsThe PPP MIB affords the network operator the ability to configure and control the PPP links of a particular system, including the PPP authentication protocols. This represents a security risk.
Kastenholz [Page 11]
RFC 1472 PPP/Security MIB June 1993 7. References[1] Rose M., and K. McCloghrie, "Structure and Identification of
Kastenholz [Page 12]
RFC 1472 PPP/Security MIB June 1993
[11] Lloyd, B., and W. Simpson, "PPP Authentication Protocols", RFC
8. Author's Address
Frank Kastenholz FTP Software, Inc. 2 High Street North Andover, Mass 01845 USA