Re: Netsnmpv5.8 possible security flaw

Wes Hardaker via Net-snmp-coders <[email protected]>
Newsgroups gmane.network.net-snmp.devel
Message-ID <[email protected]>
Madhusudhana R <[email protected]> writes:

> Can you please let me know whether this feature is added newly in v5.8
> or it was an existing feature in v5.7.3 ?
> If it is a new feature in v5.8, is there a way to toggle some MACRO
> value to make sure an user with authpriv protocol will always responds
> in encrypted way?

It's not new at all; that behavior has been around since the creation of
the SNMPv3 code within Net-SNMP (which at the time was called UCD-SNMP,
showing how old this concept is).  At the time, encryption wasn't even
possible for everyone deploying the code (and the only encryption
supported was DES).  The world tended to also believe that
authentication (ensuring packets weren't modified) was a "must have" but
encryption was merely a "would be nice if you could, but it's not critical".
-- 
Wes Hardaker
Please mail all replies to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.