Re: snmp v3 usm issue in create/change user password

Dave Shield <[email protected]>
Newsgroups gmane.network.net-snmp.user
Message-ID <CAKoMtGYtWH4ajwcA5Gkd4n5NmHN8AVukV4TwQikg=LBVYJtz+g@mail.gmail.com>
On 21 May 2012 11:51, Suresh kumar <[email protected]> wrote:
> 1.       Clone an existing user into a new user (in this case the new user
>     will be having the same password of the user used for cloning)
>
> 2.       Change the password of newly created user.


Yes - this is essentially the procedure laid out for the creation of SNMPv3
users in RFC 3414.   See the DESCRIPTION of usmUserTable for the
precise details of the recommended procedure.

The main difference is that the official procedure recommends creating
the user as an inactive entry, changing the password for that user, and
then activating the entry.   So there would never be a time when the
cloned-from-user password would be valid for retrieving actual
management data.    (The clone-from-users are typically *only* used
for this purpose, and wouldn't normally have any access to the rest
of the agent).

   The procedure laid out in RFC 3414 also includes a certain amount
of error checking, which is omitted above.   But the main thing is that
the new user should be created as an inactive entry.

Dave

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Net-snmp-users mailing list
[email protected]
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/listinfo/net-snmp-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.