Security
7705 SAR OS System Management Guide
119
authentication
Syntax
authentication
{[
none
] | [[
hash
]
{
md5
key-1
|
sha
key-1
}
privacy
{
none
|
des-key
key-2
}]
Context
config>system>security>user>snmp
Description
This command configures the authentication and encryption method the user must use in order to be
validated by the 7705 SAR. SNMP authentication allows the device to validate the managing node that
issued the SNMP message and determine if the message has been tampered with. The authentication
protocol can either be HMAC-MD5-96 or HMAC-SHA-96.
The user password is encrypted first by the MD5/SHA/DES algorithm. The output of the algorithm is
always a fixed-length string (key). Copy the
password
key and paste the output in the appropriate
authentication
command
key
parameter.
Default
authentication none - no authentication is configured and privacy cannot be configured
Parameters
none —
do not use authentication. If
none
is specified, then privacy cannot be configured.
hash —
when
hash
is not specified, unencrypted characters can be entered. When
hash
is
configured, all specified keys are stored in an encrypted format in the configuration file. The
password must be entered in encrypted form when the
hash
parameter is used.
md5
key-1
—
the MD5 authentication key is stored in an encrypted format. The minimum key
length is determined by the
config
>
system
>
security
>
password
>
minimum-length
value.
The maximum length is 16 octets (32 printable characters).
The complexity of the key is determined by the
complexity
command.
sha
key-1
—
the
sha
authentication key is stored in an encrypted format. The minimum key length
is determined by the
config
>
system
>
security
>
password
>
minimum-length
value. The
maximum length is 20 octets (40 printable characters).
The complexity of the key is determined by the
complexity
command.
privacy none —
do not perform SNMP packet encryption
privacy des-key
key-2
—
configure the des-key for SNMP packet encryption. This key is stored
in an encrypted format. The minimum key length is determined by the
config
>
system
>
security
>
password
>
minimum-length
value. The maximum length is
16 octets (32 printable characters). If privacy is configured, then
authentication
must be
enabled.
To remove a previously configured des-key, enter
privacy none
.
The complexity of the key is determined by the
complexity
command.
Default
privacy none
Summary of Contents for 7705 SAR
Page 10: ...List of Figures 10 7705 SAR OS System Management Guide...
Page 14: ...About This Guide 14 7705 SAR OS System Management Guide...
Page 64: ...Security Configuration Procedures 64 7705 SAR OS System Management Guide...
Page 168: ...Configuration Notes 168 7705 SAR OS System Management Guide...
Page 354: ...Standards and Protocol Support 354 7705 SAR OS System Management Guide...
Page 356: ...2015 Alcatel Lucent All rights reserved 3HE 09688 AAAA TQZZA Edition 01...