You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SNMP4j的SNMP v3 Trap监听器AuthNoPriv(MD5/SHA)模式异常

SNMP4j SNMP v3 Trap监听器AuthNoPriv模式认证失败问题

问题描述

使用SNMP4j实现SNMP v3 Trap监听器时,NoAuthPriv模式可正常接收Trap,但AuthNoPriv(MD5认证)模式始终触发认证失败错误。已确认网络设备与USM用户的协议、密码完全匹配,且相同配置在pysnmp中可正常运行。

实现代码

Trap监听器初始化

TransportMapping<UdpAddress> trapTransport = new DefaultUdpTransportMapping(new UdpAddress("0.0.0.0/<some_port>"));
snmp = new Snmp(trapTransport);
snmp.addCommandResponder(this::processTrap);
MessageDispatcherImpl messageDispatcher = (MessageDispatcherImpl) snmp.getMessageDispatcher();
messageDispatcher.addAuthenticationFailureListener(this::processFailedTrap);
USM usm = new USM();
SecurityModels.getInstance().addSecurityModel(usm);
SecurityProtocols.getInstance().addPredefinedProtocolSet(SecurityProtocols.SecurityProtocolSet.maxCompatibility);
snmp.listen();

USM用户配置

// NoAuthPriv模式用户
OctetString noAuthSecurityName = new OctetString("ADMIN");
byte[] noAuthSecurityEngineID = makeEngineId("some valid value");
UsmUser noAuthUser = new UsmUser(noAuthSecurityName, null, null, 
        null, null, OctetString.fromByteArray(noAuthSecurityEngineID));
snmp.getUSM().addUser(noAuthUser);

// AuthNoPriv(MD5)模式用户
OctetString MD5SecurityName = new OctetString("ADMIN");
byte[] MD5securityEngineID = makeEngineId("some valid value 1");
UsmUser MD5User = new UsmUser(MD5SecurityName, AuthMD5.ID, new OctetString("ADMINTEST"),
        null, null, OctetString.fromByteArray(MD5securityEngineID));
snmp.getUSM().addUser(MD5User);

错误信息

Received Failed Trap: 1408, org.snmp4j.asn1.BERInputStream@3b7a6a2a, SnmpConstants.SNMPv3_USM_AUTHENTICATION_FAILURE

补充发现(2024年10月1日)

对比发现pysnmp生成的认证摘要长度为12字节,而SNMP4j生成的摘要长度为16字节,怀疑这是认证失败的根源。


问题分析与解决方案

核心原因

SNMPv3 USM标准中,MD5认证使用的是HMAC-MD5-96算法,要求截取MD5哈希结果的前12字节(96位)作为认证摘要。pysnmp默认遵循该标准,但SNMP4j中直接使用AuthMD5.ID时,会使用完整的16字节MD5哈希,导致与设备端的摘要不匹配,触发认证失败。

修复步骤

  1. 替换认证协议为HMAC-MD5-96
    修改AuthNoPriv用户的代码,将AuthMD5.ID替换为AuthMD596.ID(SNMP4j提供的标准HMAC-MD5-96协议常量):
UsmUser MD5User = new UsmUser(MD5SecurityName, AuthMD596.ID, new OctetString("ADMINTEST"),
        null, null, OctetString.fromByteArray(MD5securityEngineID));
  1. 显式注册HMAC-MD5-96协议
    如果maxCompatibility配置未自动加载该协议,可手动添加:
SecurityProtocols.getInstance().addAuthenticationProtocol(new AuthMD596());
  1. 验证EngineID一致性
    确保设备端的SNMP EngineID与代码中makeEngineId生成的字节数组完全一致,EngineID不匹配会直接导致USM认证失败。

  2. 检查密码编码
    确认SNMP4j与设备端使用相同的字符编码(如UTF-8)处理认证密码,避免因编码差异生成不同的认证密钥。


内容的提问来源于stack exchange,提问作者justTesting

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 19:46:21