CUPS SNMP should not scan the entire local subnet by default

Bug #345015 reported by Justin Ellison
20
This bug affects 2 people
Affects Status Importance Assigned to Milestone
cups (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

Binary package hint: cupsys

There is a bug in Launchpad somewhere where users where complaining that the SNMP backend in CUPS was disabled. The bug was resolved in Intrepid, and it does indeed work now.

Unfortunately, it works a bit too well for many enterprise users.

In Intrepid, CUPS will by default, scan the entire local subnet of the host for printers responding to SNMP. In the enterprise, this sets off many alarms on various NIDS and firewalls.

I think maybe a happy medium would be to leave the SNMP backend enabled, so that users can easily set it up, but limit the SNMP polling to just the localhost.

This can be done by changing /etc/cups/snmp.conf to read
Address 127.0.0.1
instead of
Address @LOCAL

This particular problem caught me, so I wrote a blog post about it. I have received quite a few comments from other enterprise users thanking me for the tip. My blog is very low traffic, the fact that it has any comments at all shows it's affecting quite a few people. http://www.sysadminsjourney.com/2008/11/05/disable-snmp-printer-scanning-in-ubuntu-intrepid

Revision history for this message
Phillip Susi (psusi) wrote :

Hardy has reached end of life, and this package is not present in later releases. Closing all related bugs.

Changed in cupsys (Ubuntu):
status: New → Invalid
Revision history for this message
steve.horsley (steve-horsley) wrote : Re: [Bug 345015] Re: CUPS SNMP should not scan the entire local subnet by default

But the bug still exists. And has existed in every version of Ubuntu since
hardy.
This packet was just captured on Xubuntu 13.04, one such packet is
broadcast every time I click the + icon in system-config-printer to add a
new printer.

20:49:59.203607 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP
(17), length 71)
    192.168.8.7.56274 > 192.168.8.255.161: [udp sum ok] { SNMPv1 {
GetRequest(28) R=1 .1.3.6.1.2.1.25.3.2.1.2.1 } }

On 6 June 2013 16:11, Phillip Susi <email address hidden> wrote:

> Hardy has reached end of life, and this package is not present in later
> releases. Closing all related bugs.
>
> ** Changed in: cupsys (Ubuntu)
> Status: New => Invalid
>
> --
> You received this bug notification because you are subscribed to a
> duplicate bug report (525291).
> https://bugs.launchpad.net/bugs/345015
>
> Title:
> CUPS SNMP should not scan the entire local subnet by default
>
> To manage notifications about this bug go to:
> https://bugs.launchpad.net/ubuntu/+source/cupsys/+bug/345015/+subscriptions
>

Revision history for this message
Phillip Susi (psusi) wrote :

Hrm.. I could have sworn I changed that message to refer you to the cups package instead if it is still an issue.

affects: cupsys (Ubuntu) → cups (Ubuntu)
Changed in cups (Ubuntu):
status: Invalid → New
Revision history for this message
gf (gf-interlinks-deactivatedaccount) wrote :

Hello Justin,
Thank you for submitting this bug and reporting a problem with cups and printing. You made this bug report some time ago and Ubuntu has been updated since then.

Could you confirm that this is no longer a problem and that we can close the ticket?
If it is still a problem, are you still interested in finding a solution to this bug?
If you are, could you let us know, and in the current version, run the following (only once):
apport-collect BUGNUMBER
and upload the updated logs and and any other logs that are relevant for this particular issue.

Thank you again for helping make Ubuntu better.
G

Changed in cups (Ubuntu):
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for cups (Ubuntu) because there has been no activity for 60 days.]

Changed in cups (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.