Re: Urgent - Time synchronization packet - does encryption required or not

"Dave Shield" <[email protected]>
Newsgroups gmane.network.net-snmp.user
Message-ID <[email protected]>
On 22/11/2007, Devirani R R <[email protected]> wrote:
> Could you please clarify whether the 'Time Synchronization' packet
> should be encrypted or not. What should be the security level.

It probably doesn't matter.
The expectation of the Time Synchronization step is that the request
will fail (with notInTimeWindow - see section 3.2. 7a), before the
processing gets as far as decrypting the core PDU (3.2, 8a)


> My understanding is that the 'Time Synchronization' packet requires
> only authentication and not encryption.

It *requires* authentication, otherwise the time window calculations will
be skipped.   It *allows* encryption, but doesn't require it.

The advantage of sending an encrypted request at this stage is that if
you happen to provide a valid engineTime/Boots pair, then the remote
agent can actually process the enclosed request, and return the
required information immediately.   Similarly for the initial engineID probe.

By sending the real request as the probe, then the best case scenario
is one request/response transaction.   Worst case is three, just as in
the RFC3414 Elements of Procedure.

Dave

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Net-snmp-users mailing list
[email protected]
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/listinfo/net-snmp-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.