RE: question on key localizaton

=?ks_c_5601-1987?B?s6rH9sDN?= <[email protected]>
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
After some thought, I found that I imagined a situation
where any arbitrary pair of engines want to communicate with each other.
In this kind of situation, an engine should know all the others' keys
and different keys on every engines are meaningless.

However, this is generally not the case.
A comminication takes place between a manager  ( or one of few managers ) and an agent
and a agent need not to know another agent's key. ( except for a proxy agent. )

However we still be very cautious not to be stolen the manager box because 
it knows many keys on many other authoritative engines.  :-)

Thank you for all your kind replies.


-----Original Message-----
From: Juergen Schoenwaelder [mailto:[email protected]]
Sent: Friday, November 15, 2002 12:14 AM
To: [email protected]
Cc: [email protected]
Subject: Re: question on key localizaton



>>>>> =?ks c 5601-1987?B?s6rH9sDN?= writes:

ks> According to key localization algorithm ( specified in RFC2574
ks> section 2.6 ), authentication keys ( or privacy keys ) on every
ks> authoritative engines are all different for a single user.  Why is
ks> this necessary ?

If you steal a box and extract the key out of the box, you are not
able to talk to use this key to talk to other boxes. This is a
feature, not a bug.

/js

-- 
Juergen Schoenwaelder    <http://www.informatik.uni-osnabrueck.de/schoenw/>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.