Bug ID 532181: SNMP passphrases appear to change each time they are displayed in TMSH

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 11.6.5, 11.6.5.1, 11.6.5.2, 11.6.5.3, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2, 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 12.1.5.3, 12.1.6, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5, 13.1.3.6, 13.1.4, 13.1.4.1, 13.1.5, 13.1.5.1, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.0.1.1

Fixed In:
14.1.0

Opened: Jul 08, 2015

Severity: 3-Major

Symptoms

When SNMPv3 users are configured with authentication and privacy passwords, the TMSH display of encrypted passwords appears to change at each redisplay.

Impact

This makes it appear that the passwords are changing when only their encrypted representation has been updated, which might give incorrect information to monitoring systems that automatically detect configuration changes.

Conditions

Using TMSH to repeatedly display SNMPv3 user's encrypted authentication and privacy passwords.

Workaround

There is no workaround at this time.

Fix Information

TMSH display has been changed so that both the shallow encrypted and master key encrypted versions of the password display (the two keywords are auth-password/auth-password-encrypted and privacy-password/privacy-password-encrypted). This eliminates the issue of the SNMP passphrases appearing to change each time they are displayed in TMSH. To avoid triggering a false positive for configuration changes, monitoring systems should watch the auth-password and privacy-password values (not the deprecated -encrypted values). Note: The auth-password-encrypted and privacy-password-encrypted keywords have been deprecated but display for backwards compatibility.

Behavior Change

TMSH display has been changed so that both the shallow encrypted and master key encrypted versions of the password display (the two keywords are auth-password/auth-password-encrypted and privacy-password/privacy-password-encrypted). The auth-password-encrypted and privacy-password-encrypted keywords have been deprecated but display for backwards compatibility. Note: To avoid triggering a false positive for configuration changes, monitoring systems should watch the auth-password and privacy-password values (not the deprecated -encrypted values).

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips