<?xml version="1.0" encoding="US-ASCII"?>
<!DOCTYPE rfc SYSTEM "rfc2629.dtd">
<?xml-stylesheet type='text/xsl' href='rfc2629.xslt' ?>

<!-- processing instructions (for a complete list and description,
     see http://xml.resource.org/authoring/README.html -->

<?rfc rfcedstyle="yes" ?> 
<?rfc toc="yes"?>
<?rfc tocompact="yes"?>
<?rfc tocdepth="3"?>
<?rfc symrefs="yes"?> 
<?rfc sortrefs="yes" ?>
<?rfc compact="yes" ?>
<?rfc subcompact="no" ?>
<!-- end of list of processing instructions -->

<rfc number="7124" category="std"
     ipr="trust200902"
     updates="5066" submissionType="IETF">

<front>

<title abbrev="EFMCu Interfaces MIB">
  Ethernet in the First Mile Copper (EFMCu) Interfaces MIB
</title>

<author initials="E." surname="Beili" fullname="Edward Beili">
  <organization>Actelis Networks</organization>
  <address>
    <postal>
      <street>Bazel 25</street>
      <city>Petach-Tikva</city>
      <code>49103</code>
      <country>Israel</country>
    </postal>
    <phone>+972-73-237-6852</phone>
    <email>edward.beili@actelis.com</email>
  </address>
</author>

<date month="February" year="2014"/>

<area>Operations and Management</area>

<keyword>Network Management</keyword>
<keyword>Simple Network Management Protocol</keyword>
<keyword>SNMP</keyword>
<keyword>Management Information Base</keyword>
<keyword>MIB</keyword>
<keyword>2BASE-TL</keyword>
<keyword>10PASS-TS</keyword>
<keyword>802.3ah</keyword>
<keyword>EFM</keyword>
<keyword>PAF</keyword>
<keyword>PME</keyword>
<keyword>Interface</keyword>
<keyword>Stack</keyword>
<keyword>Bonding</keyword>

<abstract>
 <t>
  This document updates RFC 5066.
  It amends that specification by informing the Internet community
  about the transition of the EFM&nbhy;CU&nbhy;MIB module from the concluded IETF Ethernet
  Interfaces and Hub MIB Working Group to the Institute
  of Electrical and Electronics Engineers (IEEE) 802.3 working group.
 </t>
</abstract>

</front>

<middle>

<section title="Introduction">
 <t>
  RFC 5066 <xref target="RFC5066"/> defines two MIB modules:
  <list>
   <t>EFM-CU-MIB, with a set of objects for managing 10PASS-TS and
      2BASE-TL Ethernet in the First Mile Copper (EFMCu) interfaces;</t>
   <t>IF-CAP-STACK-MIB, with a set of objects describing cross-connect
      capability of a managed device with multi-layer (stacked)
      interfaces, extending the stack management objects in the
      Interfaces Group MIB and the Inverted Stack Table MIB modules.</t>
  </list>
 </t>
 <t>
  With the conclusion of the <xref target="HUBMIB"/> working group,
  the responsibility for the maintenance and further development of
  a MIB module for managing 2BASE-TL and 10PASS-TS interfaces
  has been transferred to the
  Institute of Electrical and Electronics Engineers (IEEE) 802.3
  <xref target="IEEE802.3"/> working group.
  In 2011, the IEEE developed
 the IEEE8023&nbhy;EFM&nbhy;CU&nbhy;MIB module,
  based on the original EFM-CU-MIB module <xref target="RFC5066"/>.
  The current revision of IEEE8023-EFM-CU-MIB is defined in
  IEEE Std 802.3.1-2013 <xref target="IEEE802.3.1"/>. 
 </t>
 <t>
  The IEEE8023-EFM-CU-MIB and EFM-CU-MIB MIB modules can coexist.
  Existing deployments of the EFM-CU-MIB need not be upgraded, but
  operators using the MIB should expect that new equipment will use the
  IEEE8023-EFM-CU-MIB.
 </t>
 <t>
  Please note that the IF-CAP-STACK-MIB module was not transferred to IEEE
  and remains as defined in RFC 5066. This memo provides an updated
  security considerations section for that module, since the original
  RFC did not list any security considerations for IF&nbhy;CAP&nbhy;STACK&nbhy;MIB.
 </t>
</section>

<section title="The Internet-Standard Management Framework">
 <t>
  For a detailed overview of the documents that describe the current
  Internet-Standard Management Framework, please refer to
  section 7 of RFC 3410 <xref target="RFC3410"/>.
 </t>
 <t>
  The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
  "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY",
  and "OPTIONAL" in this document are to be interpreted as described
  in RFC 2119 <xref target="RFC2119"/>.
 </t>
</section>

<section title="Mapping between EFM-CU-MIB and IEEE8023-EFM-CU-MIB">
 <t>

  The current version of IEEE8023-EFM-CU-MIB, defined in IEEE Std
  802.3.1-2013, has MODULE-IDENTITY of ieee8023efmCuMIB with an object
  identifier allocated under the { iso(1) iso&nbhy;identified&nbhy;organization(3) 
  ieee(111) standards&nbhy;association&nbhy;numbered&nbhy;series&nbhy;standards(2) 
  lan&nbhy;man&nbhy;stds(802) ieee802dot3(3) ieee802dot3dot1mibs(1) } sub&nbhy;tree.
 </t>
 <t>
  The EFM-CU-MIB has MODULE-IDENTITY of efmCuMIB with an object
  identifier allocated under the mib-2 sub-tree.
 </t>
 <t>
  The names of the objects in the first version of the IEEE8023&nbhy;EFM&nbhy;CU&nbhy;MIB
  are identical to those in the EFM-CU-MIB. However, since both MIB modules
  have different OID values, they can coexist, allowing the management of the
  newer IEEE MIB-based devices alongside the legacy IETF MIB-based devices.
 </t>
</section>

<section title="Updating the MIB Modules">
 <t>
  With the transfer of the responsibility for maintenance and further
  development of the EFM-CU-MIB module to the IEEE 802.3 working group,
  the EFM-CU-MIB defined in RFC 5066 becomes the last version of
  that MIB module.
 </t>
 <t> 
  All further development of the EFM Copper Interfaces MIB
  will be done by the IEEE 802.3 working group in the IEEE8023-EFM-CU-MIB
  module. Requests and comments pertaining to EFM Copper Interfaces
  MIB should be sent to the IEEE 802.3.1 task force, currently chartered with
  MIB development, via its mailing list
  <xref target="LIST802.3.1"/>.
 </t>
 <t>
  The IF-CAP-STACK-MIB remains under IETF control and is
  currently maintained by the <xref target="OPSAWG"/> working group.
 </t>
</section>

<section title="Security Considerations">
 <t>
  There are no managed objects defined in the IF-CAP-STACK-MIB module
  with a MAX-ACCESS clause of read-write and/or read-create. So, if this
  MIB module is implemented correctly, then there is no risk that an
  intruder can alter or create any management objects of this MIB
  module via direct SNMP SET operations.
 </t>
 <t>
  Some of the readable objects in this MIB module (i.e., objects with
  a MAX-ACCESS other than not-accessible) may be considered sensitive or
  vulnerable in some network environments.
 </t>
 <t>
  In particular, ifCapStackStatus and ifInvCapStackStatus can identify
  cross-connect capability of multi-layer (stacked) network
  interfaces, potentially revealing the underlying hardware
  architecture of the managed device.
 </t>
 <t>
  It is thus important to control even GET and/or NOTIFY access to these
  objects and possibly to even encrypt the values of these objects when sending
  them over the network via SNMP.
 </t>
 <t>
  SNMP versions prior to SNMPv3 did not include adequate security.
  Even if the network itself is secure (for example by using IPsec),
  there is no control as to who on the secure network is
  allowed to access and GET/SET (read/change/create/delete) the objects
  in this MIB module.
 </t>
 <t>
  Implementations SHOULD provide the security features described by the   
  SNMPv3 framework (see <xref target="RFC3410"/>), and implementations
  claiming compliance to the SNMPv3 standard MUST include full support for
  authentication and privacy via the User-based Security Model (USM)
  <xref target="RFC3414"/> with the AES cipher algorithm
  <xref target="RFC3826"/>.
  Implementations MAY also provide support for the Transport Security Model
  (TSM) <xref target="RFC5591"/> in combination with a secure transport such
  as SSH <xref target="RFC5592"/> or TLS/DTLS <xref target="RFC6353"/>.
 </t>
 <t>
  Further, deployment of SNMP versions prior to SNMPv3 is NOT
  RECOMMENDED. Instead, it is RECOMMENDED to deploy SNMPv3 and to
  enable cryptographic security.  It is then a customer/operator
  responsibility to ensure that the SNMP entity giving access to an
  instance of this MIB module is properly configured to give access to
  the objects only to those principals (users) that have legitimate
  rights to indeed GET or SET (change/create/delete) them.
 </t>
</section>

<section title="Acknowledgments">
 <t>
   This document was produced by the OPSAWG working
   group, whose efforts were advanced by the contributions of
   the following people (in alphabetical order):
  <list>
   <t>Dan Romascanu</t>
   <t>David Harrington</t>
   <t>Michael MacFaden</t>
   <t>Tom Petch</t>
  </list>
 </t>
 <t>
   This document updates RFC 5066, authored by Edward Beili of
   Actelis Networks, and produced by the now-concluded
   HUBMIB working group.
 </t>
</section>

</middle>

<back>

<references title="Normative References">

  <?rfc include="reference.RFC.2119.xml"?>
  <?rfc include="reference.RFC.3414.xml"?>
  <?rfc include="reference.RFC.3826.xml"?>
  <?rfc include="reference.RFC.5066.xml"?>

</references>

<references title="Informative References">

  <?rfc include="reference.RFC.3410.xml"?>
  <?rfc include="reference.RFC.5591.xml"?>
  <?rfc include="reference.RFC.5592.xml"?>
  <?rfc include="reference.RFC.6353.xml"?>

  <reference anchor="LIST802.3.1" target="http://www.ieee802.org/3/be/reflector.html">
    <front>
      <title>802.3 MIB Email Reflector</title>
      <author>
        <organization>IEEE</organization>
	<address>
          <email>stds-802-3-mib@listserv.ieee.org</email>
	</address>
      </author>
      <date/>
    </front>
  </reference>

  <reference anchor="HUBMIB" target="http://datatracker.ietf.org/wg/hubmib/charter/">
    <front>
      <title>Ethernet Interfaces and Hub MIB (hubmib) Charter</title>
      <author>
        <organization>IETF</organization>
      </author>
      <date/>
      <workgroup>HUBMIB</workgroup>
    </front>
  </reference>

  <reference anchor="IEEE802.3" target="http://www.ieee802.org/3">
    <front>
      <title>802.3 Ethernet Working Group</title>
      <author>
        <organization>IEEE</organization>
      </author>
      <date/>      
      <workgroup>802.3</workgroup>
   </front>
  </reference> 

  <reference anchor="IEEE802.3.1" target="http://standards.ieee.org/getieee802/download/802.3.1-2013.pdf">
    <front>
      <title>
        IEEE Standard for Management Information Base (MIB)
        Definitions for Ethernet
      </title>
      <author>
        <organization>IEEE</organization>
      </author>
      <date day="14" month="June" year="2013"/>
    </front>
    <seriesInfo name="IEEE Std" value="802.3.1-2013"/>

  </reference>

  <reference anchor="OPSAWG" target="http://datatracker.ietf.org/wg/opsawg/charter/">
    <front>
      <title>Operations and Management Area Working Group (opsawg) Charter</title>
      <author>
        <organization>IETF</organization>
	<address>
	  <email>opsawg@ietf.org</email>
	</address>
      </author>
      <date/>      
      <workgroup>OPSAWG</workgroup>
    </front>
  </reference>

</references>

</back>

</rfc>
