This is a discussion on Re: access control and non-default contexts within the SNMP Coders forums, part of the Networking and Network Related category; On Tue, 5 Sep 2006 14:03:20 +0100 Dave wrote: DS> It turns out that this change has ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
On Tue, 5 Sep 2006 14:03:20 +0100 Dave wrote:
DS> It turns out that this change has also affected the default behaviour DS> slightly. Up to now, these convenience directives have registered an DS> entry in the vacmAccessTable with a prefix context match on "" - thus DS> matching *ALL* contexts by default. Following my latest patches, the DS> same directive would now register an *exact* context match on "" - DS> thus applying to the default context only. DS> DS> I'm inclined to leave things as they stand - this feels a more secure DS> arrangement, and is probably in line with default expectations. But DS> it does result in a minor change in behaviour, so I wouldn't object if DS> the consensus was to switch back to the previous, more open DS> configuration. So long as we're talking 5.4+, and there is a way for the user to specify something to get the old behaviour (i.e. a prefix context match on ""), then I suppose it isn't too big a deal. I'd also say that a change in default behaviour warrants a note in the NEWS file. ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=...057&dat=121642 _______________________________________________ Net-snmp-coders mailing list Net-snmp-coders@lists.sourceforge.net https://lists.sourceforge.net/lists/...et-snmp-coders |