RE: Netsnmpv5.8 possible security flaw

Madhusudhana R <[email protected]>
Newsgroups gmane.network.net-snmp.devel
Message-ID <VI1PR0602MB27991E6BE2AE6DBDA2EC8B67B08A0@VI1PR0602MB2799.eurprd06.prod.outlook.com>
Thanks Wes. 

Can you please let me know whether this feature is added newly in v5.8 or it was an existing feature in v5.7.3 ?
If it is a new feature in v5.8, is there a way to toggle some MACRO value to make sure an user with authpriv protocol will always responds in encrypted way? 

Thanks in advance.

Regards,
Madhu

-----Original Message-----
From: Wes Hardaker [mailto:[email protected]] 
Sent: Tuesday, January 08, 2019 12:46 PM
To: Madhusudhana R <[email protected]>
Cc: [email protected]
Subject: Re: Netsnmpv5.8 possible security flaw

CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe.


Madhusudhana R <[email protected]> writes:

> With Netsnmp v5.8  upgraded to my project (which was already working 
> with v5.7.3), I am finding one problem which is as described below.
>
> An user is created in agent (which is netsnmp v5.8)

How did you configure the access control of the agent?  Specifically, if you have a line like "rwuser NAME" in it, you MUST change it to "rwuser NAME priv" to force encryption-only traffic.  Otherwise the agent will answer with both encrypted and unencrypted requests (but still authenticated).  I suspect that this is your issue, and your network management software is attempting (and succeeding) at falling back to unencrypted.

--
Wes Hardaker
Please mail all replies to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.