Re: A discussion about moving to GitHub from SF (again)

2019-01-08 Thread Bart Van Assche
On 1/2/19 2:28 PM, Wes Hardaker via Net-snmp-coders wrote: Previously [1] we agreed to moved at least the code base to GitHub, with work on moving the wiki and other things as well. Shortly after that decision was made, GitHub was bought out by MS and the consensus changed to "hold and wait till

RE: Netsnmpv5.8 possible security flaw

2019-01-08 Thread Madhusudhana R
Thanks Wes. -Original Message- From: Wes Hardaker [mailto:[email protected]] Sent: Tuesday, January 08, 2019 10:08 PM To: Madhusudhana R Cc: Wes Hardaker ; [email protected] Subject: Re: Netsnmpv5.8 possible security flaw CAUTION: This email originated

Re: EXTERNAL: Re: 5.7.3 | snmptrap not populating EngineBoots or EngineTime for snmp v3 traps

2019-01-08 Thread Wes Hardaker via Net-snmp-coders
"Roedersheimer, Drew A. via Net-snmp-coders" writes: > Denis Hainsworth wrote: > > Dug into this some more. I see whats happening and not sure if its a bug > > per se but > > I do agree that if there is a non-buggy trap sender its all working > > properly so will > > close the bug with some co

Re: Change default rwuser default security level

2019-01-08 Thread Wes Hardaker via Net-snmp-coders
Magnus Fromreide writes: > I suppose the default value of the access control is "auth", the man > page didn't say what the effects of that was? > > I think this is a bad idea as a default since that works against the > "secure by default" ideal - if someone want to loosen restrictions > then the

Re: Netsnmpv5.8 possible security flaw

2019-01-08 Thread Wes Hardaker via Net-snmp-coders
Madhusudhana R writes: > Can you please let me know whether this feature is added newly in v5.8 > or it was an existing feature in v5.7.3 ? > If it is a new feature in v5.8, is there a way to toggle some MACRO > value to make sure an user with authpriv protocol will always responds > in encrypted

Change default rwuser default security level (Was: Netsnmpv5.8 possible security flaw)

2019-01-08 Thread Magnus Fromreide
On Mon, Jan 07, 2019 at 11:16:02PM -0800, Wes Hardaker via Net-snmp-coders wrote: > Madhusudhana R writes: > > > With Netsnmp v5.8 upgraded to my project (which was already working with > > v5.7.3), I am finding one > > problem which is as described below. > > > > An user is created in agent

RE: Netsnmpv5.8 possible security flaw

2019-01-08 Thread Madhusudhana R
Thanks Wes. Can you please let me know whether this feature is added newly in v5.8 or it was an existing feature in v5.7.3 ? If it is a new feature in v5.8, is there a way to toggle some MACRO value to make sure an user with authpriv protocol will always responds in encrypted way? Thanks in a