RE: question on key localizaton
Randy Presuhn <[email protected]>
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Message-ID | <[email protected]> |
Hi - > From: "???" <[email protected]> > To: "Wes Hardaker" <[email protected]> > Cc: "Uri Blumenthal" <[email protected]>, <[email protected]> > Subject: RE: question on key localizaton > Date: Sun, 17 Nov 2002 17:53:41 +0900 > Message-ID: <[email protected]> > In-Reply-To: <[email protected]> ... > Ok, This is the point. > I took it for granted that the above common secName and its key can also be used for get or set request > by some evil agent to a righteous agent. > This can be blocked by access control mechanism, right ? Yes. IF the security administrator decides that it's an acceptible risk to employ the same userName for generating informs, then this administrator would be smart to put that userName in a VACM group with severely limited access rights by using appropriate values for vacmAccessReadViewName, vacmAccessWriteViewName, and vacmAccessNotifyViewName. ... > snmpv3 agent engine from scratch within 2 months, ... Good luck. You'll need it. Obtaining reasonable performance from GetNext/GetBulk under VACM is tricky, especially if you're supporting AgentX. Have fun. ------------------------------------------------------ Randy Presuhn BMC Software, Inc. SJC-1.3141 [email protected] 2141 North First Street Tel: +1 408 546-1006 San José, California 95131 USA ------------------------------------------------------ My opinions and BMC's are independent variables. ------------------------------------------------------