ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
snmp_v3.h File Reference

SNMPv3: the message framing and the User-based Security Model (PROTOCORE_ENABLE_SNMP_V3). More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

SNMPv3: the message framing and the User-based Security Model (PROTOCORE_ENABLE_SNMP_V3).

Authenticated and optionally encrypted SNMP on top of the same MIB the community framings reach.

RFC 3412 sec 6 gives the message: SNMPv3Message ::= SEQUENCE { msgVersion, msgGlobalData HeaderData, msgSecurityParameters OCTET STRING, msgData ScopedPduData }, where HeaderData is msgID, msgMaxSize, msgFlags and msgSecurityModel, and a ScopedPDU is contextEngineID, contextName and the PDU. RFC 3412 sec 6.4 defines the msgFlags bits authFlag, privFlag and reportableFlag.

RFC 3414 sec 2.4 gives msgSecurityParameters for USM: msgAuthoritativeEngineID, msgAuthoritativeEngineBoots, msgAuthoritativeEngineTime, msgUserName, msgAuthenticationParameters and msgPrivacyParameters. This agent is the authoritative engine, so it answers discovery (RFC 3414 sec 4) with a Report PDU naming usmStatsUnknownEngineIDs, and enforces the 150-second time window of RFC 3414 sec 2.2.3. Every failure is reported as the matching usmStats counter of RFC 3414 sec 5.

One authPriv user is configured:

  • Authentication: usmHMAC192SHA256AuthProtocol (RFC 7860 sec 8), HMAC-SHA-256 truncated to 24 octets (RFC 7860 sec 4.1). The digest is computed over the whole message with msgAuthenticationParameters replaced by zero octets (RFC 7860 sec 4.2.1 and sec 4.2.2).
  • Privacy: usmAesCfb128Protocol (RFC 3826), CFB128-AES-128 under the IV of RFC 3826 sec 3.1.2.1.

The decrypted, authenticated inner PDU is dispatched through the shared MIB core (SnmpAgentNs::dispatch_pdu), so all three framings expose the same objects. The localized keys are derived once in SnmpV3Ns::set_user, not per message.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file snmp_v3.h.