Re: Win32 with snmpusm and --defPrivLocalizedKey

Brendan Simon <[email protected]>
Newsgroups gmane.network.net-snmp.user
Message-ID <[email protected]>
Wes Hardaker wrote:
> BS> So I guess the win32 build does not:
> BS> * correctly implement the --defPrivLocalizedKey option
> BS> * correctly implement the "snmpusm -Cx changekey" command.
>
> Well, it's certainly not the first.  Ok, I hope.
>
> Caveat: I don't use windows.
> Plus: I wrote much of both the DH code and the snmpusm code.
>
> Lets try a different experiment to test the last bullet above:
>
> 1) run snmpusm on windows, and the snmpget with the new key on your
>    debian box.
>
> 2) run snmpusm on linux, and then snmpget with the new key on windows...
>
> That would let us narrow down the problem more if one of those didn't
> work but the other did.
>   
I have already tried that to try and diagnose the differences.

Scenario 1:
Linux "snmpusm -v 3 -l authNoPriv -u admin -a sha -A Password1 -Cx 
changekey joe" works fine.
Linux "snmpget -v 3 -l authNoPriv -u joe -a sha -A Joeseph1 <host> 
<oid>" works fine.
Linux "snmpget -v 3 -l authPriv -u joe -a sha -A Joeseph1 -x aes 
--defPrivKey=0x<key> <host> <oid>" works fine.
MSW "snmpget -v 3 -l authNoPriv -u joe -a sha -A Joeseph1 <host> <oid>" 
works fine.
 >>> MSW "snmpget -v 3 -l authPriv -u joe -a sha -A Joeseph1 -x aes 
--defPrivKey=0x<key> <host> <oid>" returns the error message "snmpget: 
USM generic error"

Using "-D ALL" I can see that the message "usm: Can't set AES iv." (line 
1506) is printed.  This may help narrow down the problem.

Scenario 2:
 >>> MSW "snmpusm -v 3 -l authNoPriv -u admin -a sha -A Password1 -Cx 
changekey joe" returns and error message "Unknown command" followed by 
the usage output.
NOTE: MSW "snmpusm passwd" also results in the same error "Unknown command"
NOTE: MSW "snmpusm create" appears to complete successfully.

I can see how the "changekey" command could produce "Unknown command" by 
the following lines in snmplib/snmpusm.c

    #if defined(HAVE_OPENSSL_DH_H) && defined(HAVE_LIBCRYPTO)
        } else if (strcmp(argv[arg], CMD_CHANGEKEY_NAME) == 0) {


Looking at the header files in the win32 directory, I would suggest that 
HAVE_LIBCRYPTO is not defined and most likely the reason as to "Unknown 
command" error.

However "passwd" is not surrounded by any #if statements !!!

Cheers, Brendan.


-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
_______________________________________________
Net-snmp-users mailing list
[email protected]
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/listinfo/net-snmp-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.