5. 安全考虑事项 (Security Considerations)
5. 安全考虑事项 (Security Considerations)
此 MIB 中定义了若干 management objects, 其 MAX-ACCESS clause 为 read-write. 在某些网络环境中, 这些 objects 可能被视为敏感或脆弱. 在没有适当保护的 non-secure environment 中支持 SET operations 可能会对网络操作产生负面影响.
SNMPv1 本身不是 secure environment. 即使网络本身是安全的 (例如使用 IPSec), 仍然无法控制安全网络中的哪些人被允许访问并 GET/SET (read/change) 此 MIB 中的 objects.
建议 implementors 考虑 SNMPv3 framework 提供的安全特性. 具体而言, 建议使用 User-based Security Model STD 62, RFC 3414 [RFC3414] 和 View-based Access Control Model STD 62, RFC 3415 [RFC3415].
随后由 customer/user 负责确保向此 MIB 实例提供访问的 SNMP entity 得到正确配置, 只允许确实拥有合法权利 GET 或 SET (change) 这些 objects 的 principals (users) 访问这些 objects.