Re: high-security SNMPv3 setup?

Chris Bartram <[email protected]>
Newsgroups gmane.network.net-snmp.user
Message-ID <[email protected]>
Starting with as-shipped new install of Net-SNMP version: 5.3.2.2 on a RHEL x86_64 system

config files:

/etc/snmp/snmpd.conf
/var/net-snmp/snmpd.conf (persistent data file)
 

user: remotereadonly
pass: randompass
passphrase: "really secure passphrase"
 
I want as-secure-as-possible read-only access from a remote server

authProtocol (-a SHA)
privProtocol (-x AES)
securityLevel (-l authPriv)


add to /etc/snmp/snmpd.conf:

rouser remotereadonly priv system


 
add to /var/net-snmp/snmpd.conf:

createUser remotereadonly SHA randompass DES "really secure passphrase"

stop and restart snmpd

Is that all I need to do?

Do I really need to create a dummy user first; then clone the one user I need?

If I send SNMPv3 traps; on the receiving system does the userid need RO or RW?

 
"The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionate, to have it make some difference that you have lived and lived well". (Ralph Waldo Emerson)


>________________________________
> From: Chris Bartram <[email protected]>
>To: "[email protected]" <[email protected]> 
>Sent: Monday, July 2, 2012 8:41 AM
>Subject: high-security SNMPv3 setup?
> 
>
>Is there an up-to-date tutorial online somewhere on setting up Net SNMP SNMPv3 agents on RHEL5 systems? Full encryption/ AES security - plus certificates? - and something I can easily replicate across hundreds of systems?
>
>
>I've found lots of "tutorials" online - many with conflicting info - and most date back several years.
>
>
>Thanks,
> Chris Bartram
>
> 
>"The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionate, to have it make some difference that you have lived and lived well". (Ralph Waldo Emerson)
>------------------------------------------------------------------------------
>Live Security Virtual Conference
>Exclusive live event will cover all the ways today's security and 
>threat landscape has changed and how IT managers can respond. Discussions 
>will include endpoint security, mobile security and the latest in malware 
>threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
>_______________________________________________
>Net-snmp-users mailing list
>[email protected]
>Please see the following page to unsubscribe or change other options:
>https://lists.sourceforge.net/lists/listinfo/net-snmp-users
>
>
>

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/

_______________________________________________
Net-snmp-users mailing list
[email protected]
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/listinfo/net-snmp-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.