Thanks Wes. 

-----Original Message-----
From: Wes Hardaker [mailto:harda...@users.sourceforge.net] 
Sent: Tuesday, January 08, 2019 10:08 PM
To: Madhusudhana R <madhusudhan...@in.abb.com>
Cc: Wes Hardaker <harda...@users.sourceforge.net>; 
net-snmp-coders@lists.sourceforge.net
Subject: Re: Netsnmpv5.8 possible security flaw

CAUTION: This email originated from outside of the organization. Do not click 
links or open attachments unless you recognize the sender and know the content 
is safe.


Madhusudhana R <madhusudhan...@in.abb.com> writes:

> Can you please let me know whether this feature is added newly in v5.8 
> or it was an existing feature in v5.7.3 ?
> If it is a new feature in v5.8, is there a way to toggle some MACRO 
> value to make sure an user with authpriv protocol will always responds 
> in encrypted way?

It's not new at all; that behavior has been around since the creation of the 
SNMPv3 code within Net-SNMP (which at the time was called UCD-SNMP, showing how 
old this concept is).  At the time, encryption wasn't even possible for 
everyone deploying the code (and the only encryption supported was DES).  The 
world tended to also believe that authentication (ensuring packets weren't 
modified) was a "must have" but encryption was merely a "would be nice if you 
could, but it's not critical".
--
Wes Hardaker
Please mail all replies to net-snmp-coders@lists.sourceforge.net


_______________________________________________
Net-snmp-coders mailing list
Net-snmp-coders@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/net-snmp-coders

Reply via email to