Re: Urgent - Time synchronization packet - does encryption required or not
"Dave Shield" <[email protected]>
| Newsgroups | gmane.network.net-snmp.user |
|---|---|
| Message-ID | <[email protected]> |
On 22/11/2007, Devirani R R <[email protected]> wrote: > Could you please clarify whether the 'Time Synchronization' packet > should be encrypted or not. What should be the security level. It probably doesn't matter. The expectation of the Time Synchronization step is that the request will fail (with notInTimeWindow - see section 3.2. 7a), before the processing gets as far as decrypting the core PDU (3.2, 8a) > My understanding is that the 'Time Synchronization' packet requires > only authentication and not encryption. It *requires* authentication, otherwise the time window calculations will be skipped. It *allows* encryption, but doesn't require it. The advantage of sending an encrypted request at this stage is that if you happen to provide a valid engineTime/Boots pair, then the remote agent can actually process the enclosed request, and return the required information immediately. Similarly for the initial engineID probe. By sending the real request as the probe, then the best case scenario is one request/response transaction. Worst case is three, just as in the RFC3414 Elements of Procedure. Dave ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ _______________________________________________ Net-snmp-users mailing list [email protected] Please see the following page to unsubscribe or change other options: https://lists.sourceforge.net/lists/listinfo/net-snmp-users