RE: Help needed
"Wijnen, Bert (Bert)" <[email protected]> Fri, 29 Aug 2003 15:28:41 +0200
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Message-ID | <7D5D48D2CAA3D84C813F5B154F43B1550245C681@nl0006exch001u.nl.lucent.com> |
Inline > -----Original Message----- > From: srinivasan R [mailto:[email protected]] > Sent: vrijdag 29 augustus 2003 12:26 > To: [email protected]; [email protected]; [email protected] > Subject: Help needed > > > Hi All, > > This is regarding the scenario wherein the SnmpEngineBoots > value reached its maximum value, 2147483647. > > The possible solution suggested by RFC 3414 is given below > > " In order to reset an SNMP engine whose snmpEngineBoots value has > reached the value 2147483647, manual intervention is required. The > engine must be physically visited and re-configured, either with a > new snmpEngineID value, or with new secret values for the > authentication and privacy protocols of all users known to that SNMP > engine. Note that even if an SNMP engine re-boots once a second that > it would still take approximately 68 years before the max value of > 2147483647 would be reached." > > Here my understanding is that changing the secret values of the > authentication and privacy protocols of all users known to that > SNMP Engine enables the manager to further communicate with the > authoritative agent(with same snmpEngineID) > > I have a couple of doubts. They are, > > (i) Changing the secret values resets the snmpEngineBoots of > that SNMP Engine to zero by default. > I don't think that we specified that. So I would assume such is implementation dependent. Besides, if you have a reasonable set of users, I do not see that it is easy to change the secrets all at once via a single SNMP SET. I don't think we intended that you would be able to reset all secrets via one (or multiple) SNMP SET requests and that such would reset snmpEngineBoots value. > (ii) In what way changing the secret values affects the > snmpEngineBoots value ?/ what is the relation between > snmpEngineBoots and secret values. > The idea is (I am not the best security expert here, so maybe Uri or Russ or so can jump in) that the snmpEngineBoots is part of the "authentication-timeliness" check and it only makes sense if the messages are at least authenticated, so if they have at least secuirtLevel of authNoPriv. So my thinking is that if you reset all secreats, that starting anew with an snmpEngineBoots at zero is OK, because any old (captured) messages that anyone would want to replay can then never be valid, because they would not match the MAC based on the new secrets. Security specialists, pls chime in here. > (iii) If I reconfigure a new snmpEngineID, then the users > already configured in the device are accessible through the > new snmpEngineID. Am I right here ? > Well, normally (as RECOMMENDED), the managed device keeps all secrets in a localized form. So one would need to re-generate the localized secrets at the managed (authoritative) engine as well. But other than that, I think that you can indeed re-use (or continue to use) the existing users. Hope this explains/helps. Bert > > Thanks in advance, > > R. srinivasan > > _________________________________________________________________ > ICICI's NRI services. They make life easy. > http://server1.msn.co.in/msnspecials/nriservices/index.asp > Find out more. >