MIBs Depot

CISCO-PKI-MIB

Registered at
1.3.6.1.4.1.9.9.854
Last updated
2014-10-16 00:00
Organization
Cisco Systems, Inc.
Revisions
2014-10-15 00:00
Namespace
cisco
Source file
CISCO-PKI-MIB
Digest
sha256:c500f67208529a7d581de03873967e08e74277f553d3ee6bf0de320eee5183c9

Description

description

Contact

Cisco Systems Customer Service Postal: 170 W Tasman Drive San Jose, CA 95134 USA Tel: +1 800 553-NETS E-mail: cs-<list>@cisco.com

Imports

FromSymbols
CISCO-SMIciscoMgmt
SNMPv2-CONFMODULE-COMPLIANCE, NOTIFICATION-GROUP, OBJECT-GROUP
SNMPv2-SMICounter32, Integer32, MODULE-IDENTITY, NOTIFICATION-TYPE, OBJECT-IDENTITY, OBJECT-TYPE, Unsigned32, iso
SNMPv2-TCDisplayString, TEXTUAL-CONVENTION, TimeInterval

Imported by

Nothing in this corpus imports this module.

Load order

Every file a consumer needs in order to load this module, dependencies first.

CISCO-PKI-MIB
CISCO-SMI
SNMPv2-CONF
SNMPv2-SMI
SNMPv2-TC

Objects

NameOIDSyntaxAccessStatus
ciscoPkiMIBNotifs
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.1
ciscoPkiMIBObjects
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.2
ciscoPkiConfiguration
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.2.1
ciscoPkiEnrollmentProfile
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.2.1.1
ciscoPkiEnrollmentTable
OBJECT-TYPE
Please enter the Table Description here.
1.3.6.1.4.1.9.9.854.2.1.1.1not-accessiblecurrent
enrollProfEntry
OBJECT-TYPE
An entry (conceptual row) in the xxxTable.
1.3.6.1.4.1.9.9.854.2.1.1.1.1not-accessiblecurrent
enrollProfLabel
OBJECT-TYPE
Unique value to display Enrollment Label. If enrollment profiles are not present, string size of 0 will show nothing.
1.3.6.1.4.1.9.9.854.2.1.1.1.1.3DisplayString (SIZE(0..255))not-accessiblecurrent
enrolCredentials
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.4DisplayStringread-onlycurrent
authLocation
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.5DisplayStringread-onlycurrent
authMethod
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.6DisplayStringread-onlycurrent
authVrf
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.7DisplayStringread-onlycurrent
authSourceInter
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.8DisplayStringread-onlycurrent
enrolMethod
OBJECT-TYPE
Enrollment method will be displayed which will be used to authenticate and enroll. If enrollment method is configured as terminal, this parameter gives enrollment terminal If enrollment method is configured with url, this parameter returns enrollment url ip_addresss If vrf is configured as part of enrollment url, it will be shown as part of enrollment url ip_address vrf interface
1.3.6.1.4.1.9.9.854.2.1.1.1.1.9DisplayString (SIZE(0..255))read-onlycurrent
enrolLocation
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.10DisplayStringread-onlycurrent
enrolVrf
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.11DisplayStringread-onlycurrent
enrolSourceInter
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.12DisplayStringread-onlycurrent
reenrolMethod
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.13DisplayStringread-onlycurrent
reenrolLocation
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.14DisplayStringread-onlycurrent
reenrolVrf
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.15DisplayStringread-onlycurrent
reenrolSourceInter
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.1.1.1.1.16DisplayStringread-onlycurrent
ciscoPkiTrustpoints
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.2.1.2
pkiTPTable
OBJECT-TYPE
Please enter the Table Description here.
1.3.6.1.4.1.9.9.854.2.1.2.1not-accessiblecurrent
pkiTPEntry
OBJECT-TYPE
An entry (conceptual row) in the xxxTable.
1.3.6.1.4.1.9.9.854.2.1.2.1.1not-accessiblecurrent
tpLabel
OBJECT-TYPE
Unique name of Trustpoint Label. When there is no trustpoint configured, size 0 shows no trustpoint configured.
1.3.6.1.4.1.9.9.854.2.1.2.1.1.1DisplayString (SIZE(0..255))not-accessiblecurrent
subjectName
OBJECT-TYPE
Subject name configured under the trustpoint will be returned
1.3.6.1.4.1.9.9.854.2.1.2.1.1.2DisplayString (SIZE(0..255))read-onlycurrent
subjectAltName
OBJECT-TYPE
subject alternate name configured under the trustpoint which can be used while generating the csr.
1.3.6.1.4.1.9.9.854.2.1.2.1.1.3DisplayString (SIZE(0..50))read-onlycurrent
aaaListInfo
OBJECT-TYPE
Returns AAA authorization list to be used configured under trustpoint. AAA authorization list will be used during peer certificate validations etc. In order to access information on AAA list, please check AAA MIB corresponding to this AAA label.
1.3.6.1.4.1.9.9.854.2.1.2.1.1.4DisplayString (SIZE(0..50))read-onlycurrent
enrollmentConfig
OBJECT-TYPE
Enrollment configuration which is configured under the trustpoint will be returned.
1.3.6.1.4.1.9.9.854.2.1.2.1.1.5DisplayString (SIZE(0..255))read-onlycurrent
vrfConfig
OBJECT-TYPE
VRF interface configured under trustpoint which can be used for enrollment and obtaining CRL's
1.3.6.1.4.1.9.9.854.2.1.2.1.1.6DisplayString (SIZE(0..50))read-onlycurrent
sourceInter
OBJECT-TYPE
source Interface configured under trustpoint.
1.3.6.1.4.1.9.9.854.2.1.2.1.1.7DisplayString (SIZE(0..50))read-onlycurrent
autoEnroll
OBJECT-TYPE
If autoEnroll is configured under the trustpoint, autoEnroll returns with the percentage configured. If the percentage is not configured, but auto-enroll is configured under trustpoint, this parameter return auto-enroll. If percentage is configured, parameter returns auto-enroll <percentage>
1.3.6.1.4.1.9.9.854.2.1.2.1.1.8DisplayString (SIZE(0..20))read-onlycurrent
keyPairLabel
OBJECT-TYPE
Displays keypairLabel associated to this trustpoint if it is enrolled. During authentication, we wont generate the keypair Label.
1.3.6.1.4.1.9.9.854.2.1.2.1.1.10DisplayString (SIZE(0..255))read-onlycurrent
revocationMethod
OBJECT-TYPE
This object displays revocation check configured on the device. If nothing is configured under the trustpoint, by default revocation-check crl will be updated.
1.3.6.1.4.1.9.9.854.2.1.2.1.1.11DisplayString (SIZE(0..50))read-onlycurrent
hashAlgo
OBJECT-TYPE
Hash algorithm configured under the trustpoint. This will be used while selecting the HASH algorithm when CA server responded with GetCACapabilities list. Default value is sha1
1.3.6.1.4.1.9.9.854.2.1.2.1.1.12DisplayStringread-onlycurrent
trustpointState
OBJECT-TYPE
Trustpoint state displays following 1) Authenticated - Trustpoint is in Authenticated state. 2) Enrolled - Trustpoint is authenticated and enrolled. Certificate state is granted. 3) Pending - Trustpoint is authenticated but enrollment is in pending state. This means CA server returned PENDING for the router certificate. 4) None - Trustpoint is neither authenticated nor enrolled.
1.3.6.1.4.1.9.9.854.2.1.2.1.1.13DisplayString (SIZE(0..20))read-onlycurrent
ciscoPkiCertificates
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.2.2
certChainTable
OBJECT-TYPE
Please enter the Table Description here.
1.3.6.1.4.1.9.9.854.2.2.1not-accessiblecurrent
certChainEntry
OBJECT-TYPE
An entry (conceptual row) in the xxxTable.
1.3.6.1.4.1.9.9.854.2.2.1.1not-accessiblecurrent
certChainLabel
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.2.1.1.1DisplayStringnot-accessiblecurrent
certSerialNum
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.2.1.1.2DisplayStringread-onlycurrent
certIssuerName
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.2.1.1.3DisplayStringread-onlycurrent
certStartDate
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.2.1.1.4DisplayStringread-onlycurrent
certEndDate
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.2.1.1.5DisplayStringread-onlycurrent
certType
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.2.1.1.6DisplayStringread-onlycurrent
certRemainingLife
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.2.1.1.7DisplayStringaccessible-for-notifycurrent
certTpLabel
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.2.1.1.8DisplayStringread-onlycurrent
certSubName
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.2.1.1.9DisplayStringread-onlycurrent
ciscoPkiRevocationInfo
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.2.3
ciscoPkiCRLInfo
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.2.3.1
pkiCRLTable
OBJECT-TYPE
Please enter the Table Description here.
1.3.6.1.4.1.9.9.854.2.3.1.1not-accessiblecurrent
pkiCRLEntry
OBJECT-TYPE
An entry (conceptual row) in the xxxTable.
1.3.6.1.4.1.9.9.854.2.3.1.1.1not-accessiblecurrent
crlTpLabel
OBJECT-TYPE
Unique trustpoint Label
1.3.6.1.4.1.9.9.854.2.3.1.1.1.1DisplayStringnot-accessiblecurrent
issuerName
OBJECT-TYPE
CRL Issuer name
1.3.6.1.4.1.9.9.854.2.3.1.1.1.2DisplayString (SIZE(0..255))read-onlycurrent
sequenceNumb
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.3.1.1.1.3DisplayString (SIZE(0..255))read-onlycurrent
nextUpdate
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.3.1.1.1.4DisplayString (SIZE(0..255))read-onlycurrent
crlSize
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.3.1.1.1.5Unsigned32 (0..4294967294)read-onlycurrent
deltaCRLFlag
OBJECT-TYPE
This object specifies the storage type for this conceptual row. The following columnar objects are allowed to be writable when the storageType of this conceptual row is permanent(4): (replace with list of columns)
1.3.6.1.4.1.9.9.854.2.3.1.1.1.6Unsigned32read-onlycurrent
ciscoPkiOSCPInfo
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.2.3.2
pkiOCSPTable
OBJECT-TYPE
Please enter the Table Description here.
1.3.6.1.4.1.9.9.854.2.3.2.1not-accessiblecurrent
pkiOCSPEntry
OBJECT-TYPE
An entry (conceptual row) in the xxxTable.
1.3.6.1.4.1.9.9.854.2.3.2.1.1not-accessiblecurrent
ocspTpLabel
OBJECT-TYPE
Please enter the object description here
1.3.6.1.4.1.9.9.854.2.3.2.1.1.1DisplayString (SIZE(0..255))not-accessiblecurrent
responderID
OBJECT-TYPE
An identifier of the responder (DN name or a hash of its key)
1.3.6.1.4.1.9.9.854.2.3.2.1.1.2DisplayString (SIZE(0..255))read-onlycurrent
thisUpdate
OBJECT-TYPE
The issuing time of the revocation information.
1.3.6.1.4.1.9.9.854.2.3.2.1.1.3DisplayString (SIZE(0..255))read-onlycurrent
nexUpdate
OBJECT-TYPE
The issuing time of the revocation information that will update that one.
1.3.6.1.4.1.9.9.854.2.3.2.1.1.4DisplayString (SIZE(0..255))read-onlycurrent
ciscoPkiMIBConform
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.3
ciscoPkiMIBCompliances
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.3.1
ciscoPkiMIBGroups
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.854.3.2

Notifications

NameOIDStatus
ciscoPkiCertInstallAlert
NOTIFICATION-TYPE
When a certificate is installed on the device, notification will be sent with following information. a) Certificates Serial number b) Certificate Issuer-name c) Certificate Subject name d) Trustpoint name e) Type of certificate. (i.e. CA/ID) certificate f) Certificate Start Date g) Certificate End Date Alert will not be sent for RA certificates, trustpool certificates and self-signed non-persistent certificates.
1.3.6.1.4.1.9.9.854.1.1current
ciscoPkiCertExpiryAlert
NOTIFICATION-TYPE
Certificate Expiry alert consists of following a) Certificate Serial number b) Certificate Issuer-name c) Trustpoint name d) Type of certificate (i.e. CA/ID/SUBCA/RA) e) Certificate remaining lifetime in seconds. f) Certificate subject-name When a certificate is reaching its expiry on the router, a trap will be sent to SNMP server at regular intervals starting from 60days to till 1week. From 1week onwards daily one trap will be sent with following information a) Certificate Serial number b) Certificate Issuer-name c) Trustpoint name d) Type of certificate (i.e. CA/ID) e) Certificate remaining lifetime. Alert will not be sent if trustpoint is configured with auto-enroll and corresponding shadow certificate/rollover certificate is present provided, shadow/rollover certificates start time is same/behind certificate end time. If shadow/rollover certificate start time is ahead of certificate end time, alerts will be continued to send because shadow certificate wont be valid from certificates expiry time. Expiry alerts will not be sent for trustpool certificates.
1.3.6.1.4.1.9.9.854.1.2current

Conformance

NameOIDStatus
ciscoPkiMIBCompliance
MODULE-COMPLIANCE
This is a default module-compliance containing default object groups.
1.3.6.1.4.1.9.9.854.3.1.1current
ciscoPkiMIBMainObjectGroup
OBJECT-GROUP
The is a test group.
1.3.6.1.4.1.9.9.854.3.2.1current
ciscoPkiMIBNotificationGroup
NOTIFICATION-GROUP
Notification alert group consists of both installation and expiry notifications.
1.3.6.1.4.1.9.9.854.3.2.2current