RE: question on key localizaton
=?ks_c_5601-1987?B?s6rH9sDN?= <[email protected]>
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Message-ID | <[email protected]> |
After some thought, I found that I imagined a situation where any arbitrary pair of engines want to communicate with each other. In this kind of situation, an engine should know all the others' keys and different keys on every engines are meaningless. However, this is generally not the case. A comminication takes place between a manager ( or one of few managers ) and an agent and a agent need not to know another agent's key. ( except for a proxy agent. ) However we still be very cautious not to be stolen the manager box because it knows many keys on many other authoritative engines. :-) Thank you for all your kind replies. -----Original Message----- From: Juergen Schoenwaelder [mailto:[email protected]] Sent: Friday, November 15, 2002 12:14 AM To: [email protected] Cc: [email protected] Subject: Re: question on key localizaton >>>>> =?ks c 5601-1987?B?s6rH9sDN?= writes: ks> According to key localization algorithm ( specified in RFC2574 ks> section 2.6 ), authentication keys ( or privacy keys ) on every ks> authoritative engines are all different for a single user. Why is ks> this necessary ? If you steal a box and extract the key out of the box, you are not able to talk to use this key to talk to other boxes. This is a feature, not a bug. /js -- Juergen Schoenwaelder <http://www.informatik.uni-osnabrueck.de/schoenw/>