RE: SNMPv3 security

Michael Kirkham <[email protected]> Thu, 7 Aug 2003 14:40:14 -0700 (PDT)
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
On Thu, 7 Aug 2003, Fleischman, Eric wrote:

> It is therefore essential that the Session Key have a short lifetime in
> order to reduce the amount of available ciphertext encrypted by the same
> key and to introduce doubts whether any two ciphertexts were encrypted
> by the same or different keys. This is the most fundamental defense
> available to us as SNMPv3 end users.

Not to argue either way, but are you taking into account the fact that
each message is encrypted using a different initialization vector (derived
from the static localized key and a salt that changes with each message)?

(RFC 3414 section 8.1.1.1 for reference.)

--
Michael Kirkham
www.muonics.com