RE: question on key localizaton

Randy Presuhn <[email protected]>
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
Hi -

> From: "???" <[email protected]>
> To: "Wes Hardaker" <[email protected]>
> Cc: "Uri Blumenthal" <[email protected]>, <[email protected]>
> Subject: RE: question on key localizaton
> Date: Sun, 17 Nov 2002 17:53:41 +0900
> Message-ID: <[email protected]>
> In-Reply-To: <[email protected]>
...
> Ok, This is the point.
> I took it for granted that the above common secName and its key can also be used for get or set request
> by some evil agent to a righteous agent.
> This can be blocked by access control mechanism, right ?

Yes.  IF the security administrator decides that it's an
acceptible risk to employ the same userName for generating
informs, then this administrator would be smart to put that
userName in a VACM group with severely limited access rights
by using appropriate values for vacmAccessReadViewName,
vacmAccessWriteViewName, and vacmAccessNotifyViewName.

...
> snmpv3 agent engine from scratch within 2 months,
...

Good luck.  You'll need it.  Obtaining reasonable performance
from GetNext/GetBulk under VACM is tricky, especially if you're
supporting AgentX.  Have fun.

 ------------------------------------------------------
 Randy Presuhn          BMC Software, Inc.  SJC-1.3141
 [email protected]  2141 North First Street
 Tel: +1 408 546-1006   San José, California 95131  USA
 ------------------------------------------------------
 My opinions and BMC's are independent variables.
 ------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.