Re: Bypassing USM for internal requests.

Wes Hardaker <[email protected]>
Newsgroups gmane.network.net-snmp.devel,gmane.network.net-snmp.user
Organization Sparta
Message-ID <[email protected]>
>>>>> On Mon, 23 Jan 2006 17:49:51 +0200, "Makavy, Erez (Erez)" <[email protected]> said:

Erez> b) create a new degenerated security module. (from SNMP architecture
Erez> perspective, this is the preffered solution)

Actually the latest net-snmp release (5.3+) contains the ability to
handle a "local" security model that does not authenticate the
transaction with USM but rather just lets it go through.  It is not,
however, well documented.  It is used by the (also new) "STD"
transport that lets SNMP messages arrive and depart through
stdio/err.  See snmplib/snmpSTDDomain.c and snmplib/snmplocalsm.c.  Note
that the UCD_MSG_FLAG_TUNNELED flag must be set in the PDU for the
local security model to ignore the security of how the packet got there.

-- 
Wes Hardaker
Sparta, Inc.


-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems?  Stop!  Download the new AJAX search engine that makes
searching your log files as easy as surfing the  web.  DOWNLOAD SPLUNK!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.