data:image/s3,"s3://crabby-images/3b65b/3b65b1f0483d7ea5bc5d672037c171bf65bbaddd" alt="artisan WIENER Mini Crate 475 User Manual Download Page 30"
User’s Manual
475 Mini Crate Series
W-I
e
–
N
e
-R
Plein & Baus GmbH
12/11/2017
27
3.5.9 Creating a Save System
To get a save system, the authKeys and privKeys for all users must be changed, and the passwords
must be kept confidential (don’t forget the user “wiener”).
The device EEPROM stores localized keys (if the user uses the same key for different hardware
devices, the real key used for this device is altered in a random way, using the crates MAC address.)
So if read access to one EEPROM is achieved, this does not disclose the non-localized keys used by
the operator of the system.
Then SNMPv2 access via community strings must be disabled (you might omit “public” if you don’t
want do disable read only access). This can be done by changing the community string to a zero string
(no characters, length 0). This can by done by using the following commands:
Test snmp community access (using community “private” here)
$ snmpget -v 2c -c private 192.168.91.222 sysDescr.0
SNMPv2-MIB::sysDescr.0 = STRING: WIENER Crate (UEP6000 2.22, UEL6 4.23.2731.0, UEL6-BL 2.2733.0)
Set all community strings to ""
$ snmpset
-v 2c -c wiener
–
m +WIENER-CRATE-MIB 192.168.91.222 snmpCommunityName.public = ""
snmpCommunityName.public = ""
$ snmpset
-v 2c
-c wiener
–
m +WIENER-CRATE-MIB 192.168.91.222 snmpCommunityName.private = ""
snmpCommunityName.private = ""
$ snmpset
-v 2c
-c wiener
–
m +WIENER-CRATE-MIB 192.168.91.222 snmpCommunityName.admin = ""
snmpCommunityName.admin = ""
$ snmpset
-v 2c
-c wiener
–
m +WIENER-CRATE-MIB 192.168.91.222 snmpCommunityName.guru = ""
snmpCommunityName.guru = ""
WIENER-CRATE-MIB::snmpCommunityName.private = ""
$ snmpset
-v 2c
-c wiener
–
m +WIENER-CRATE-MIB 192.168.91.222 snmpCommunityName.5 = ""
snmpCommunityName.5 = ""
Verify. There should be no response, the community is ignored.
$ snmpget -v 2c -c private 192.168.91.222 sysDescr.0
Timeout: No Response from 192.168.91.222.
3.5.10
Restoring Factory Defaults
If authentication keys got lost, or if a lesser security level is required, the only way is to set the device
back to factory defaults.
If SNMP access is possible, use the command
$ snmpset -m +WIENER-CRATE-MIB -v 3 -u guru -l authPriv -a MD5 -A MySecret -x DES -X MySecret
192.168.91.222 sysFactoryDefaults.0 = 1