Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1019791 > unrolled thread
| Started by | James Greig <james@host-it.co.uk> |
|---|---|
| First post | 2020-07-30 15:10 +0200 |
| Last post | 2020-08-03 19:00 +0200 |
| Articles | 16 — 11 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#966544: snmpd: extend option broken after update James Greig <james@host-it.co.uk> - 2020-07-30 15:10 +0200
Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update Craig Small <csmall@debian.org> - 2020-07-31 03:00 +0200
Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update James Greig <James@host-it.co.uk> - 2020-07-31 10:00 +0200
Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update Christian Balzer <chibi@gol.com> - 2020-07-31 05:40 +0200
Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update Axel Uhl <axel.uhl@gmx.de> - 2020-08-01 18:00 +0200
Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update Albertas Sileika <a.sileika@gmail.com> - 2020-07-31 06:20 +0200
Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update Craig Small <csmall@debian.org> - 2020-07-31 06:30 +0200
Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update Albertas Sileika <a.sileika@gmail.com> - 2020-07-31 06:40 +0200
Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update Ramon Cahenzli <rca@psy-q.ch> - 2020-07-31 09:10 +0200
Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update Rudi Daemen <info@kratjebierhosting.nl> - 2020-07-31 10:10 +0200
Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update Zubrick <zubrick@number6.ch> - 2020-07-31 11:40 +0200
Bug#966544: snmpd: extend option broken after update Salvatore Bonaccorso <carnil@debian.org> - 2020-08-01 08:40 +0200
Bug#966544: snmpd: extend option broken after update James Greig <James@host-it.co.uk> - 2020-08-01 18:40 +0200
Bug#966544: snmpd: extend option broken after update Salvatore Bonaccorso <carnil@debian.org> - 2020-08-04 19:20 +0200
Bug#966544: snmpd: extend option broken after update James Greig <James@host-it.co.uk> - 2020-08-04 20:40 +0200
Bug#966544: Switching from extend to pass for custom endpoints Ian Campbell <ijc@debian.org> - 2020-08-03 19:00 +0200
| From | James Greig <james@host-it.co.uk> |
|---|---|
| Date | 2020-07-30 15:10 +0200 |
| Subject | Bug#966544: snmpd: extend option broken after update |
| Message-ID | <AygtP-5Es-1@gated-at.bofh.it> |
Package: snmpd Version: 5.7.3+dfsg-1.7+deb9u2 Severity: important Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system breaks the ability to use 'extend' in snmpd. After updating on any stretch system and restarting snmpd this error will appear:- Warning: Unknown token: extend It's likely the latest binary build of this package has not included options to enable extend and/or other extras. *** End of the template - remove these template lines *** -- System Information: Debian Release: 9.13 APT prefers oldstable-updates APT policy: (500, 'oldstable-updates'), (500, 'oldstable') Architecture: amd64 (x86_64) Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores) Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB:en (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) Versions of packages snmpd depends on: ii adduser 3.115 ii debconf [debconf-2.0] 1.5.61 ii init-system-helpers 1.48 ii libc6 2.24-11+deb9u4 ii libsnmp-base 5.7.3+dfsg-1.7+deb9u2 ii libsnmp30 5.7.3+dfsg-1.7+deb9u2 ii lsb-base 9.20161125 snmpd recommends no packages. Versions of packages snmpd suggests: pn snmptrapd <none> -- debconf information excluded
[toc] | [next] | [standalone]
| From | Craig Small <csmall@debian.org> |
|---|---|
| Date | 2020-07-31 03:00 +0200 |
| Subject | Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update |
| Message-ID | <AyryV-3Ex-1@gated-at.bofh.it> |
| In reply to | #1019791 |
[Multipart message — attachments visible in raw view] — view raw
Hi James, That would have been intentional, the EXTEND MIB has major security issues. - Craig On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote: > Package: snmpd > Version: 5.7.3+dfsg-1.7+deb9u2 > Severity: important > > Dear Maintainer, > > *** Reporter, please consider answering these questions, where appropriate > *** > > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system > breaks the ability to use 'extend' in snmpd. > > After updating on any stretch system and restarting snmpd this error will > appear:- > > Warning: Unknown token: extend > > It's likely the latest binary build of this package has not included > options to > enable extend and/or other extras. > > *** End of the template - remove these template lines *** > > > -- System Information: > Debian Release: 9.13 > APT prefers oldstable-updates > APT policy: (500, 'oldstable-updates'), (500, 'oldstable') > Architecture: amd64 (x86_64) > > Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores) > Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), > LANGUAGE=en_GB:en (charmap=UTF-8) > Shell: /bin/sh linked to /bin/dash > Init: systemd (via /run/systemd/system) > > Versions of packages snmpd depends on: > ii adduser 3.115 > ii debconf [debconf-2.0] 1.5.61 > ii init-system-helpers 1.48 > ii libc6 2.24-11+deb9u4 > ii libsnmp-base 5.7.3+dfsg-1.7+deb9u2 > ii libsnmp30 5.7.3+dfsg-1.7+deb9u2 > ii lsb-base 9.20161125 > > snmpd recommends no packages. > > Versions of packages snmpd suggests: > pn snmptrapd <none> > > -- debconf information excluded > > _______________________________________________ > Pkg-net-snmp-devel mailing list > Pkg-net-snmp-devel@alioth-lists.debian.net > https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-net-snmp-devel
[toc] | [prev] | [next] | [standalone]
| From | James Greig <James@host-it.co.uk> |
|---|---|
| Date | 2020-07-31 10:00 +0200 |
| Subject | Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update |
| Message-ID | <Ayy7n-7IG-1@gated-at.bofh.it> |
| In reply to | #1019876 |
[Multipart message — attachments visible in raw view] — view raw
Hi, Though I do appreciate that security should come above everything. I have to agree with everyone else here it seems surprising that it has just been removed like this. We use it in read-only ourselves as well and it has broken a lot of monitoring. Kind regards James Greig From: Craig Small <csmall@debian.org> Sent: 31 July 2020 01:46 To: James Greig <James@host-it.co.uk>; 966544@bugs.debian.org Subject: Re: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update Hi James, That would have been intentional, the EXTEND MIB has major security issues. - Craig On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk<mailto:james@host-it.co.uk>> wrote: Package: snmpd Version: 5.7.3+dfsg-1.7+deb9u2 Severity: important Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system breaks the ability to use 'extend' in snmpd. After updating on any stretch system and restarting snmpd this error will appear:- Warning: Unknown token: extend It's likely the latest binary build of this package has not included options to enable extend and/or other extras. *** End of the template - remove these template lines *** -- System Information: Debian Release: 9.13 APT prefers oldstable-updates APT policy: (500, 'oldstable-updates'), (500, 'oldstable') Architecture: amd64 (x86_64) Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores) Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB:en (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) Versions of packages snmpd depends on: ii adduser 3.115 ii debconf [debconf-2.0] 1.5.61 ii init-system-helpers 1.48 ii libc6 2.24-11+deb9u4 ii libsnmp-base 5.7.3+dfsg-1.7+deb9u2 ii libsnmp30 5.7.3+dfsg-1.7+deb9u2 ii lsb-base 9.20161125 snmpd recommends no packages. Versions of packages snmpd suggests: pn snmptrapd <none> -- debconf information excluded _______________________________________________ Pkg-net-snmp-devel mailing list Pkg-net-snmp-devel@alioth-lists.debian.net<mailto:Pkg-net-snmp-devel@alioth-lists.debian.net> https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-net-snmp-devel
[toc] | [prev] | [next] | [standalone]
| From | Christian Balzer <chibi@gol.com> |
|---|---|
| Date | 2020-07-31 05:40 +0200 |
| Subject | Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update |
| Message-ID | <Ayu3L-5jm-5@gated-at.bofh.it> |
| In reply to | #1019791 |
Hello Craig, These issues, do they warrant utterly breaking things w/o any recourse short of recompiling things for many, many users that use the extend feature? Especially given the fact that SNMP traffic tends to be on private networks and the feature not being enabled by default in the config. At the very least a "this will break things, abort now" missive during upgrade would have been nice. If upstream can't/won't fix this snmpd has lost it's usefulness for me in the long run compared to other data collectors. Regards, Christian On Fri, 31 Jul 2020 10:46:29 +1000 Craig Small <csmall@debian.org> wrote: > Hi James, > That would have been intentional, the EXTEND MIB has major security > issues. > > - Craig > > > On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote: > > > Package: snmpd > > Version: 5.7.3+dfsg-1.7+deb9u2 > > Severity: important > > > > Dear Maintainer, > > > > *** Reporter, please consider answering these questions, where appropriate > > *** > > > > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system > > breaks the ability to use 'extend' in snmpd. > > > > After updating on any stretch system and restarting snmpd this error will > > appear:- > > > > Warning: Unknown token: extend > > > > It's likely the latest binary build of this package has not included > > options to > > enable extend and/or other extras. > > > > *** End of the template - remove these template lines *** > > > > > > -- System Information: > > Debian Release: 9.13 > > APT prefers oldstable-updates > > APT policy: (500, 'oldstable-updates'), (500, 'oldstable') > > Architecture: amd64 (x86_64) > > > > Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores) > > Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), > > LANGUAGE=en_GB:en (charmap=UTF-8) > > Shell: /bin/sh linked to /bin/dash > > Init: systemd (via /run/systemd/system) > > > > Versions of packages snmpd depends on: > > ii adduser 3.115 > > ii debconf [debconf-2.0] 1.5.61 > > ii init-system-helpers 1.48 > > ii libc6 2.24-11+deb9u4 > > ii libsnmp-base 5.7.3+dfsg-1.7+deb9u2 > > ii libsnmp30 5.7.3+dfsg-1.7+deb9u2 > > ii lsb-base 9.20161125 > > > > snmpd recommends no packages. > > > > Versions of packages snmpd suggests: > > pn snmptrapd <none> > > > > -- debconf information excluded -- Christian Balzer Network/Systems Engineer chibi@gol.com Rakuten Mobile Inc.
[toc] | [prev] | [next] | [standalone]
| From | Axel Uhl <axel.uhl@gmx.de> |
|---|---|
| Date | 2020-08-01 18:00 +0200 |
| Subject | Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update |
| Message-ID | <Az25s-1Ek-7@gated-at.bofh.it> |
| In reply to | #1019883 |
[Multipart message — attachments visible in raw view] — view raw
Same here. snmpd broke over night, now my mrtg which is reporting, e.g., disk temperatures using a smartctl-based cannot be reported anymore, and I was wondering why this cron job now keeps flooding my inbox... All intranet, all very inconvenient. As others mentioned, a warning would have been nice. Now I need to compile from sources. What a hassle! On Fri, 31 Jul 2020 12:32:05 +0900 Christian Balzer <chibi@gol.com> wrote: > > Hello Craig, > > These issues, do they warrant utterly breaking things w/o any recourse > short of recompiling things for many, many users that use the extend > feature? > Especially given the fact that SNMP traffic tends to be on private > networks and the feature not being enabled by default in the config. > > At the very least a "this will break things, abort now" missive during > upgrade would have been nice. > > If upstream can't/won't fix this snmpd has lost it's usefulness for me in > the long run compared to other data collectors. > > Regards, > > Christian > > > On Fri, 31 Jul 2020 10:46:29 +1000 Craig Small <csmall@debian.org> wrote: > > Hi James, > > That would have been intentional, the EXTEND MIB has major security > > issues. > > > > - Craig > > > > > > On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote: > > > > > Package: snmpd > > > Version: 5.7.3+dfsg-1.7+deb9u2 > > > Severity: important > > > > > > Dear Maintainer, > > > > > > *** Reporter, please consider answering these questions, where appropriate > > > *** > > > > > > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system > > > breaks the ability to use 'extend' in snmpd. > > > > > > After updating on any stretch system and restarting snmpd this error will > > > appear:- > > > > > > Warning: Unknown token: extend > > > > > > It's likely the latest binary build of this package has not included > > > options to > > > enable extend and/or other extras. > > > > > > *** End of the template - remove these template lines *** > > > > > > > > > -- System Information: > > > Debian Release: 9.13 > > > APT prefers oldstable-updates > > > APT policy: (500, 'oldstable-updates'), (500, 'oldstable') > > > Architecture: amd64 (x86_64) > > >
[toc] | [prev] | [next] | [standalone]
| From | Albertas Sileika <a.sileika@gmail.com> |
|---|---|
| Date | 2020-07-31 06:20 +0200 |
| Subject | Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update |
| Message-ID | <AyuGt-5Lv-1@gated-at.bofh.it> |
| In reply to | #1019791 |
[Multipart message — attachments visible in raw view] — view raw
Hi, It is not acceptable to remove feature without possibility to enable it again. This update breaks part of our monitoring system. Albertas On Fri, 31 Jul 2020 10:46:29 +1000 Craig Small <csmall@debian.org> wrote: > Hi James, > That would have been intentional, the EXTEND MIB has major security > issues. > > - Craig > > > On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote: > > > Package: snmpd > > Version: 5.7.3+dfsg-1.7+deb9u2 > > Severity: important > > > > Dear Maintainer, > > > > *** Reporter, please consider answering these questions, where appropriate > > *** > > > > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system > > breaks the ability to use 'extend' in snmpd. > > > > After updating on any stretch system and restarting snmpd this error will > > appear:- > > > > Warning: Unknown token: extend > > > > It's likely the latest binary build of this package has not included > > options to > > enable extend and/or other extras. > > > > *** End of the template - remove these template lines *** > > > > > > -- System Information: > > Debian Release: 9.13 > > APT prefers oldstable-updates > > APT policy: (500, 'oldstable-updates'), (500, 'oldstable') > > Architecture: amd64 (x86_64) > > > > Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores) > > Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), > > LANGUAGE=en_GB:en (charmap=UTF-8) > > Shell: /bin/sh linked to /bin/dash > > Init: systemd (via /run/systemd/system) > > > > Versions of packages snmpd depends on: > > ii adduser 3.115 > > ii debconf [debconf-2.0] 1.5.61 > > ii init-system-helpers 1.48 > > ii libc6 2.24-11+deb9u4 > > ii libsnmp-base 5.7.3+dfsg-1.7+deb9u2 > > ii libsnmp30 5.7.3+dfsg-1.7+deb9u2 > > ii lsb-base 9.20161125 > > > > snmpd recommends no packages. > > > > Versions of packages snmpd suggests: > > pn snmptrapd <none> > > > > -- debconf information excluded -- Su pagarba, Albertas Šileika
[toc] | [prev] | [next] | [standalone]
| From | Craig Small <csmall@debian.org> |
|---|---|
| Date | 2020-07-31 06:30 +0200 |
| Subject | Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update |
| Message-ID | <AyuQ9-5RC-1@gated-at.bofh.it> |
| In reply to | #1019886 |
[Multipart message — attachments visible in raw view] — view raw
I'm trying to understand why you (or anyone) would use such an insecure feature. One question, are you using in read-only mode or read-write mode? read-only mode could be enabled, but read-write probably can't be anymore. - Craig On Fri, 31 Jul 2020 at 14:15, Albertas Sileika <a.sileika@gmail.com> wrote: > Hi, > > It is not acceptable to remove feature without possibility to enable it > again. This update breaks part of our monitoring system. > > Albertas > > On Fri, 31 Jul 2020 10:46:29 +1000 Craig Small <csmall@debian.org> wrote: > > Hi James, > > That would have been intentional, the EXTEND MIB has major security > > issues. > > > > - Craig > > > > > > On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote: > > > > > Package: snmpd > > > Version: 5.7.3+dfsg-1.7+deb9u2 > > > Severity: important > > > > > > Dear Maintainer, > > > > > > *** Reporter, please consider answering these questions, where > appropriate > > > *** > > > > > > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system > > > breaks the ability to use 'extend' in snmpd. > > > > > > After updating on any stretch system and restarting snmpd this error > will > > > appear:- > > > > > > Warning: Unknown token: extend > > > > > > It's likely the latest binary build of this package has not included > > > options to > > > enable extend and/or other extras. > > > > > > *** End of the template - remove these template lines *** > > > > > > > > > -- System Information: > > > Debian Release: 9.13 > > > APT prefers oldstable-updates > > > APT policy: (500, 'oldstable-updates'), (500, 'oldstable') > > > Architecture: amd64 (x86_64) > > > > > > Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores) > > > Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), > > > LANGUAGE=en_GB:en (charmap=UTF-8) > > > Shell: /bin/sh linked to /bin/dash > > > Init: systemd (via /run/systemd/system) > > > > > > Versions of packages snmpd depends on: > > > ii adduser 3.115 > > > ii debconf [debconf-2.0] 1.5.61 > > > ii init-system-helpers 1.48 > > > ii libc6 2.24-11+deb9u4 > > > ii libsnmp-base 5.7.3+dfsg-1.7+deb9u2 > > > ii libsnmp30 5.7.3+dfsg-1.7+deb9u2 > > > ii lsb-base 9.20161125 > > > > > > snmpd recommends no packages. > > > > > > Versions of packages snmpd suggests: > > > pn snmptrapd <none> > > > > > > -- debconf information excluded > > > -- > Su pagarba, > Albertas Šileika > _______________________________________________ > Pkg-net-snmp-devel mailing list > Pkg-net-snmp-devel@alioth-lists.debian.net > https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-net-snmp-devel
[toc] | [prev] | [next] | [standalone]
| From | Albertas Sileika <a.sileika@gmail.com> |
|---|---|
| Date | 2020-07-31 06:40 +0200 |
| Subject | Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update |
| Message-ID | <AyuZP-5UT-1@gated-at.bofh.it> |
| In reply to | #1019887 |
[Multipart message — attachments visible in raw view] — view raw
We use read-only mode for monitoring custom things with nagios. Maybe it is possible to disable extend by default, but to leave possibility to enable it. In our case it is enough to have read-only mode. Albertas On Fri, Jul 31, 2020 at 7:18 AM Craig Small <csmall@debian.org> wrote: > I'm trying to understand why you (or anyone) would use such an insecure > feature. One question, are you using in read-only mode or read-write mode? > read-only mode could be enabled, but read-write probably can't be anymore. > > - Craig > > > On Fri, 31 Jul 2020 at 14:15, Albertas Sileika <a.sileika@gmail.com> > wrote: > >> Hi, >> >> It is not acceptable to remove feature without possibility to enable it >> again. This update breaks part of our monitoring system. >> >> Albertas >> >> On Fri, 31 Jul 2020 10:46:29 +1000 Craig Small <csmall@debian.org> wrote: >> > Hi James, >> > That would have been intentional, the EXTEND MIB has major security >> > issues. >> > >> > - Craig >> > >> > >> > On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote: >> > >> > > Package: snmpd >> > > Version: 5.7.3+dfsg-1.7+deb9u2 >> > > Severity: important >> > > >> > > Dear Maintainer, >> > > >> > > *** Reporter, please consider answering these questions, where >> appropriate >> > > *** >> > > >> > > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system >> > > breaks the ability to use 'extend' in snmpd. >> > > >> > > After updating on any stretch system and restarting snmpd this error >> will >> > > appear:- >> > > >> > > Warning: Unknown token: extend >> > > >> > > It's likely the latest binary build of this package has not included >> > > options to >> > > enable extend and/or other extras. >> > > >> > > *** End of the template - remove these template lines *** >> > > >> > > >> > > -- System Information: >> > > Debian Release: 9.13 >> > > APT prefers oldstable-updates >> > > APT policy: (500, 'oldstable-updates'), (500, 'oldstable') >> > > Architecture: amd64 (x86_64) >> > > >> > > Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores) >> > > Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), >> > > LANGUAGE=en_GB:en (charmap=UTF-8) >> > > Shell: /bin/sh linked to /bin/dash >> > > Init: systemd (via /run/systemd/system) >> > > >> > > Versions of packages snmpd depends on: >> > > ii adduser 3.115 >> > > ii debconf [debconf-2.0] 1.5.61 >> > > ii init-system-helpers 1.48 >> > > ii libc6 2.24-11+deb9u4 >> > > ii libsnmp-base 5.7.3+dfsg-1.7+deb9u2 >> > > ii libsnmp30 5.7.3+dfsg-1.7+deb9u2 >> > > ii lsb-base 9.20161125 >> > > >> > > snmpd recommends no packages. >> > > >> > > Versions of packages snmpd suggests: >> > > pn snmptrapd <none> >> > > >> > > -- debconf information excluded >> >> >> -- >> Su pagarba, >> Albertas Šileika >> _______________________________________________ >> Pkg-net-snmp-devel mailing list >> Pkg-net-snmp-devel@alioth-lists.debian.net >> >> https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-net-snmp-devel > > -- Su pagarba, Albertas Šileika
[toc] | [prev] | [next] | [standalone]
| From | Ramon Cahenzli <rca@psy-q.ch> |
|---|---|
| Date | 2020-07-31 09:10 +0200 |
| Subject | Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update |
| Message-ID | <AyxkZ-7sv-5@gated-at.bofh.it> |
| In reply to | #1019887 |
Hi Craig, On Fri, 31 Jul 2020 14:17:46 +1000 Craig Small <csmall@debian.org> wrote: > I'm trying to understand why you (or anyone) would use such an > insecure feature. One question, are you using in read-only mode or > read-write mode? We also use this feature in read-only mode for monitoring, and I woke up to hundreds of red sensors this morning after unattended-upgrades pulled in the new version. Am I looking in the wrong place or is there no mention of this change in the changelog? Cheers, Ramon
[toc] | [prev] | [next] | [standalone]
| From | Rudi Daemen <info@kratjebierhosting.nl> |
|---|---|
| Date | 2020-07-31 10:10 +0200 |
| Subject | Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update |
| Message-ID | <Ayyh3-81j-5@gated-at.bofh.it> |
| In reply to | #1019791 |
[Multipart message — attachments visible in raw view] — view raw
Hi, same here, woke up this morning to dozens of alert emails because extend support is suddenly "removed" without any change logs indicating this, nor in the man pages. The snmpd runs in read-only mode here as well. Alternatively, can you please provide a valid method of getting extended data into snmpd with the same ease as 'extend' feature offered? Kind regards, Rudi Daemen
[toc] | [prev] | [next] | [standalone]
| From | Zubrick <zubrick@number6.ch> |
|---|---|
| Date | 2020-07-31 11:40 +0200 |
| Subject | Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update |
| Message-ID | <AyzG9-j6-13@gated-at.bofh.it> |
| In reply to | #1019791 |
[Multipart message — attachments visible in raw view] — view raw
Hi, Same here for all the nagios alerts, and we don't have any writable snmp instance in our infrastructure only read-only. What is to question is that the original bug #965166 that implied this update proposed three different fixes that didn't imply breaking production servers and none of these fixes seem to have been considered. Disabling a feature on stable or old-stable and preventing enabling it back seems to be the worst fix possible for me. This would be a suitable change for a testing version. Regards Zubrick
[toc] | [prev] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2020-08-01 08:40 +0200 |
| Message-ID | <AyTlv-40n-1@gated-at.bofh.it> |
| In reply to | #1019791 |
Hi Felix and all, On Fri, Jul 31, 2020 at 03:36:54PM +0200, Felix Sperling wrote: > Hi, > > we were also effected from the update 5.7.3+dfsg-1.7+deb9u2 causing lots of > broken icinga checks. > > Our workaround is pinning 5.7.3+dfsg-1.7+deb9u1. > > What's unclear from the solution if 5.8 also will be available in stretch > and buster which we need. Otherwise it would be great to enable extend in > 5.7.3 for those versions. 5.8+dfsg-5 cannot go to buster and stretch, so this is not an option. For buster the update the maintainer (Craig Small) is planning for the security update is mirroring what went into unstable. As 5.7.3+dfsg-1.7+deb9u2 went out as DLA 2299-1, I'm looping in here the LTS team. LTS team: Would suggest to issue a regression update for the DLA and revisit the fix for CVE-2020-15862 to do the same, not to disable EXTEND-MIB completely but making it read-only. Hope this helps so far, Regards, Salvatore
[toc] | [prev] | [next] | [standalone]
| From | James Greig <James@host-it.co.uk> |
|---|---|
| Date | 2020-08-01 18:40 +0200 |
| Message-ID | <Az2Ia-29W-3@gated-at.bofh.it> |
| In reply to | #1020025 |
Hi, Well, hopefully LTS can fix this for those of us that are using oldstable (stretch). It almost seems like someone broke production on the oldstable version, then said, "don't worry - we've fixed it on unstable" (a version no one is using in production), then walked away :) Current work around is to either apt-mark snmpd before you upgrade if you haven't already broken it OR to run something like apt install snmpd=5.7.3+dfsg-1.7+deb9u1 libsnmp30=5.7.3+dfsg-1.7+deb9u1 to force the downgrade. Kind regards James Greig
[toc] | [prev] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2020-08-04 19:20 +0200 |
| Message-ID | <AA8Lv-2JX-7@gated-at.bofh.it> |
| In reply to | #1020025 |
Hi Felix and all, On Sat, Aug 01, 2020 at 08:37:17AM +0200, Salvatore Bonaccorso wrote: > Hi Felix and all, > > On Fri, Jul 31, 2020 at 03:36:54PM +0200, Felix Sperling wrote: > > Hi, > > > > we were also effected from the update 5.7.3+dfsg-1.7+deb9u2 causing lots of > > broken icinga checks. > > > > Our workaround is pinning 5.7.3+dfsg-1.7+deb9u1. > > > > What's unclear from the solution if 5.8 also will be available in stretch > > and buster which we need. Otherwise it would be great to enable extend in > > 5.7.3 for those versions. > > 5.8+dfsg-5 cannot go to buster and stretch, so this is not an option. > For buster the update the maintainer (Craig Small) is planning for the > security update is mirroring what went into unstable. > > As 5.7.3+dfsg-1.7+deb9u2 went out as DLA 2299-1, I'm looping in here > the LTS team. LTS team: Would suggest to issue a regression update for > the DLA and revisit the fix for CVE-2020-15862 to do the same, not to > disable EXTEND-MIB completely but making it read-only. This should be handled with DLA 2313-1[1]. [1] https://lists.debian.org/debian-lts-announce/2020/08/msg00009.html Regards, Salvatore
[toc] | [prev] | [next] | [standalone]
| From | James Greig <James@host-it.co.uk> |
|---|---|
| Date | 2020-08-04 20:40 +0200 |
| Message-ID | <AAa0W-3pS-21@gated-at.bofh.it> |
| In reply to | #1020554 |
Hi, Thanks to the LTS team for resolving for those on stretch. Kind regards James Greig
[toc] | [prev] | [next] | [standalone]
| From | Ian Campbell <ijc@debian.org> |
|---|---|
| Date | 2020-08-03 19:00 +0200 |
| Subject | Bug#966544: Switching from extend to pass for custom endpoints |
| Message-ID | <AzLYB-5qp-1@gated-at.bofh.it> |
| In reply to | #1019791 |
Hi all,
I switched from pass to extend for my custom endpoint since the latter
was not disabled with the security update. It's a bit more faff but not
intractable (just lots of boilerplate really) so maybe it's useful to
post here as a sort of recipe while things get sorted out some other
way in the packaging.
I went from snmpd.conf with (nb: /var/run/qcontrol.temp simply contains
a single integer value, nothing fancy, it's updated elsewhere):
extend .1.3.6.1.4.1.65535.1 - /bin/cat /var/run/qcontrol.temp
To one with:
pass .1.3.6.1.4.1.65535.1 /bin/bash /etc/snmp/qcontrol-mib
Where /etc/snmp/qcontrol-mib is:
#!/bin/bash
# https://sourceforge.net/p/net-snmp/code/ci/master/tree/local/passtest
PLACE=".1.3.6.1.4.1.65535.1"
OP="$1"
REQ="$2"
case "$OP" in
"-s") # SET
OP="SET"
logger -p daemon.debug "qcontrol-mib: $OP $REQ: ignored"
exit 0
;;
"-n") # GETNEXT
OP="GETNEXT"
case "$REQ" in
$PLACE|$PLACE.0|$PLACE.0.*|$PLACE.1) RET="$PLACE.1.0" ;;
*) exit 0 ;; # Nothing after this
esac
;;
"-g") # GET
OP="GET"
case "$REQ" in
$PLACE.1.0) RET="$REQ" ;;
*)
logger -p daemon.warn "qcontrol-mib: $OP $REQ: unknown"
exit 0
;;
esac
;;
esac
# GET and GETNEXT
logger -p daemon.debug "qcontrol-mib: $OP $REQ: OK"
echo "$RET"
case "$RET" in
$PLACE.1.0) echo "integer" ; printf "%d\n" $(cat /var/run/qcontrol.temp);;
esac
These were moderately useful resources:
http://www.net-snmp.org/docs/man/snmpd.conf.html (see: MIB-Specific Extension Commands)
http://net-snmp.sourceforge.net/wiki/index.php/Tut:Extending_snmpd_using_shell_scripts
https://sourceforge.net/p/net-snmp/code/ci/master/tree/local/passtest
For people who want persistent_pass instead this looked like a good
resource but I didn't follow it myself since my needs were so trivial:
https://vincent.bernat.ch/en/blog/2012-extending-netsnmp
That has links to Perl and Python helper libraries which I think you'd
likely want to use if you wanted multiple values since plumbing the
GETNEXT stuff together manually in the simple shell script case as
above would be fairly tedious.
HTH someone,
Ian.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web