RE: SNMPv3 security
David Spakes <[email protected]> Thu, 7 Aug 2003 17:21:56 -0400 (EDT)
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 7 Aug 2003, Fleischman, Eric wrote: > No user or security administrator can bear the overhead of > redistributing tens of thousands of SNMPv3 passwords. They certainly > can't regularly do this within an adequately short key lifetime > quantum in order to make the current SNMPv3 approach begin to be > viable. Egads!!! Hi Eric, SNMP Research has a policy-based configuration tool for SNMPv3 called Simple PolicyPro. It is part of a suite of applications called EnterPol (http://www.snmp.com/products/enterpol.html). Redistributing tens of thousands of SNMPv3 passwords on a regular basis is one of the design goals of Simple PolicyPro. Changing one user's password in the policy definition takes just a few mouse clicks and keystrokes in the GUI. A background process performs the necessary Set requests to the usmUserTable on all of the remote agents to which that policy is assigned. When a company has so many hosts, there's bound to be at least a few that are down or unreachable at any given point in time. Simple PolicyPro stores policy changes in a database so retries can be made over several days or longer if necessary--the behavior is configurable. Let me know if you would like a free evaluation copy. Regards, David Spakes ------------------------------------------------------------- David Spakes email: [email protected] SNMP Research voice: +1 865 573 1434 3001 Kimberlin Heights Road fax: +1 865 573 9197 Knoxville, TN 37920-9716 USA http://www.snmp.com ------------------------------------------------------------- SNMPv3 is now... the Full Internet Management Framework (RFC 3410-3418) Are your management tools secure, open, flexible, and scalable? Rely on the proven experts when taking your next step