NAME
encodekeychange - produce the KeyChange string for SNMPv3
SYNOPSIS
eennccooddeekkeeyycchhaannggee -t md5|sha1 [OPTIONS]
DESCRIPTION
eennccooddeekkeeyycchhaannggee produces a KeyChange string using the old and newpassphrases as described in Section 5 of RFC 2274 "User-based Security
Model (USM) for version 3 of the Simple Network Management Protocol(SNMPv3)". -tt option is mandatory and specifies the hash transform type
to use. The transform is used to convert passphrase to master key for a given user (Ku), convert master key to the localized key (Kul), and to hash the old Kul with the random bits. Passphrases are obtained by examining a number of sources until success (in order listed):command line options (see -NN and -OO options below);
the file $$HHOOMMEE//..ssnnmmpp//ppaasssspphhrraassee..eekk which should only contain two
lines with old and new passphrase;standard input -oorr- user input from the terminal.
OOPPTTIIOONNSS-EE [0x]
EngineID used for Kul generation. is intepreted as a hex string when preceeded by 0x, otherwise it is treated as a text string. If no is specified, it is constructed from the first IP address for the local host. -ff Force passphrases to be read from standard input.
-hh Display the help message.
-NN "
Passphrase used to generate the new Ku." -OO "
Passphrase used to generate the old Ku." -PP Turn off the prompt for passphrases when getting data from stan-
dard input.-vv Be verbose.
-VV Echo passphrases to terminal.
SEE ALSO
The localized key method is defined in RFC 2274, Sections 2.6 and A.2, and originally documented inU. Blumenthal, N. C. Hien, B. Wijnen, "Key Derivation for Net-
work Management Applications", IEEE Network Magazine, April/May issue, 1997. 4.2 Berkeley Distribution 16 Nov 2006 encodekeychange(1)