# How SNMPv3 Authentication Functions in Patator: user and auth_key Parameters Explained

> Understand SNMPv3 authentication in Patator. Learn how user and auth_key parameters define SNMPv3 usernames and secrets for secure requests using pysnmp.

- Repository: [lanjelot/patator](https://github.com/lanjelot/patator)
- Tags: deep-dive
- Published: 2026-03-05

---

**Patator implements SNMPv3 authentication by mapping the `user` parameter to the SNMPv3 username and `auth_key` to the authentication secret, ultimately constructing a pysnmp `UsmUserData` object that secures all subsequent SNMP requests.**

SNMPv3 authentication in Patator provides secure, user-based access control for network penetration testing and auditing. The open-source tool `lanjelot/patator` implements this functionality within the `SNMP_login` class in [`src/patator/patator.py`](https://github.com/lanjelot/patator/blob/main/src/patator/patator.py), translating command-line arguments into validated pysnmp security models. Understanding how the `user` and `auth_key` parameters interact with the underlying library is essential for configuring brute-force and authentication testing scenarios.

## Understanding the SNMP_login Class Architecture

### Core Implementation Location

The SNMPv3 logic resides in the `SNMP_login` class inside [`src/patator/patator.py`](https://github.com/lanjelot/patator/blob/main/src/patator/patator.py). This class handles both SNMPv1/v2c community string testing and SNMPv3 user-based authentication through its `execute` method, which orchestrates the security model construction.

## How Patator Processes user and auth_key Parameters

When the `execute` method receives `version='3'`, Patator initiates a five-step validation and construction process before issuing any network requests.

### Step 1: Protocol Validation

First, Patator validates the authentication and privacy protocols against internal lookup tables. The `auth_proto` parameter must exist in `SNMP_AUTHPROTO` (supporting MD5, SHA, or SHA-512), while `priv_proto` must be present in `SNMP_PRIVPROTO` (supporting DES or AES).

Implementation details in [`src/patator/patator.py`](https://github.com/lanjelot/patator/blob/main/src/patator/patator.py) lines 4045-4048 ensure only supported protocols proceed to credential construction.

### Step 2: Password Length Enforcement

SNMPv3 standards require minimum key lengths of 8 characters. Patator explicitly checks both `auth_key` and `priv_key` (if provided) at lines 4010-4012, returning an error response immediately if either key falls below this threshold.

### Step 3: Credential Dictionary Construction

Patator builds a `kwargs` dictionary containing:

- `authKey`: The raw value from the `auth_key` parameter
- `authProtocol`: The protocol object retrieved from `SNMP_AUTHPROTO` using the `auth_proto` argument

If `priv_key` is supplied, the dictionary also includes `privKey` and `privProtocol` entries. This construction occurs at lines 4013-4015.

### Step 4: UsmUserData Instantiation

The critical security model creation happens at line 4017. Patator instantiates `auth.UsmUserData` from the pysnmp library, passing the `user` argument (the SNMPv3 username) along with the credential dictionary constructed in the previous step. This object becomes the security model for the session.

### Step 5: Executing the SNMP Request

Finally, the built `security_model` object is passed to `get_cmd` within the asynchronous `async_cmd` method (lines 4022-4029). The response, whether successful authentication or failure message (such as `wrongDigest`), is wrapped into a `Response` object and returned to the caller.

## Practical Brute-Force Implementation

To test SNMPv3 credentials using Patator, supply dictionaries for both usernames and authentication keys:

```python

# Brute-forcing SNMPv3 logins with user and auth_key parameters

%prog host=10.0.0.1 version=3 user=FILEusers.txt auth_key=FILEpasswords.txt \
      auth_proto=sha priv_proto=aes priv_key=FILEpriv.txt \
      -x ignore:mesg=wrongDigest

```

**Parameter Breakdown:**

- **`user`**: The SNMPv3 username passed directly to the `UsmUserData` constructor
- **`auth_key`**: The authentication secret mapped to `authKey` in the pysnmp security model
- **`auth_proto`**: Hash algorithm selection (`md5`, `sha`, or `sha512`)
- **`priv_key`**: Optional encryption key for the privacy layer (maps to `privKey`)
- **`priv_proto`**: Encryption algorithm (`des` or `aes`)

This command iterates through every combination of username and password from the provided files, constructing unique `UsmUserData` instances for each attempt and issuing GET requests against `sysDescr.0`.

## Summary

- Patator's SNMPv3 support is implemented in the `SNMP_login` class within [`src/patator/patator.py`](https://github.com/lanjelot/patator/blob/main/src/patator/patator.py)
- The `user` parameter supplies the SNMPv3 username to the pysnmp `UsmUserData` constructor at line 4017
- The `auth_key` parameter provides the authentication secret, mapped to `authKey` in the credential dictionary (lines 4013-4015)
- Authentication requires keys of at least 8 characters and valid protocol selections from `SNMP_AUTHPROTO` and `SNMP_PRIVPROTO`
- Under the hood, Patator relies on the pysnmp library's `auth.UsmUserData` class to handle the actual cryptographic authentication for every request

## Frequently Asked Questions

### What is the minimum length requirement for auth_key in Patator's SNMPv3 implementation?

Patator enforces an 8-character minimum length for both `auth_key` and `priv_key` parameters to comply with SNMPv3 security standards. This validation occurs at lines 4010-4012 in [`src/patator/patator.py`](https://github.com/lanjelot/patator/blob/main/src/patator/patator.py), and attempts with shorter keys return an error response immediately without attempting network communication.

### Which authentication protocols does Patator support for SNMPv3?

According to the `SNMP_AUTHPROTO` lookup table defined in [`src/patator/patator.py`](https://github.com/lanjelot/patator/blob/main/src/patator/patator.py), Patator supports MD5, SHA, and SHA-512 for authentication. For privacy and encryption, the `SNMP_PRIVPROTO` table includes DES and AES options that can be specified via the `priv_proto` parameter.

### How does Patator handle the privacy key (priv_key) alongside auth_key?

When `priv_key` is provided, Patator includes both `privKey` and `privProtocol` entries in the credential dictionary alongside `authKey` and `authProtocol`. This complete dictionary is then passed to `auth.UsmUserData` at line 4017, enabling authenticated and encrypted SNMPv3 communication using the pysnmp library.

### What library does Patator use under the hood for SNMPv3 authentication?

Patator relies on the **pysnmp** library for all SNMP functionality. Specifically, it constructs `pysnmp.entity.config.UsmUserData` objects (referenced as `auth.UsmUserData` in the source) to manage user-based security models for SNMPv3 requests, delegating all cryptographic operations to this external dependency.