RE: question on key localizaton
"Wijnen, Bert (Bert)" <[email protected]>
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Message-ID | <F74EF3316D9CD4118D8400508BAEDCAA07615B24@nl0006exch001u.nl.lucent.com> |
I think, the bottom of sect 11.2 in rfc2574 explains it. The idea is that if one of the managed devices gets compromised, and all it has ia a localized key, then that localized key and username cannot be used to attack other managed devices. Hope this helps, Bert > -----Original Message----- > From: [email protected] [mailto:[email protected]] > Sent: donderdag 14 november 2002 15:53 > To: [email protected] > Subject: question on key localizaton > > > According to key localization algorithm ( specified in > RFC2574 section 2.6 ), > authentication keys ( or privacy keys ) on every > authoritative engines are all different for a single user. > Why is this necessary ? > Should an engine know the others' keys which are all > different for a single user for communication? > > Am I misunderstanding something? > >