MIB Viewer

DOCS-SEC-MIB

102 objects
This MIB module contains the management objects for the management of the security requirements in the DOCSIS Security Specification.
Imported Objects
CLAB-DEF-MIBclabProjDocsis
DOCS-IF3-MIB-- RFC 4001 docsIf3CmtsCmRegStatusEntry docsIf3CmtsCmRegStatusId
INET-ADDRESS-MIB-- RFC 3411 InetAddressType InetAddress InetAddressPrefixLength
SNMP-FRAMEWORK-MIB-- RFC 2580 SnmpAdminString
SNMP-TARGET-MIB-- RFC 3411 SnmpTagList
SNMPv2-CONF-- RFC 2579 OBJECT-GROUP MODULE-COMPLIANCE
SNMPv2-SMICounter32 MODULE-IDENTITY OBJECT-TYPE Unsigned32
SNMPv2-TC-- RFC 2578 TEXTUAL-CONVENTION DateAndTime MacAddress RowStatus TruthValue
OIDNameAccessStatusDescription
1.3.6.1.4.1.4491.2.1.11IdentitydocsSecMibThis MIB module contains the management objects for the management of the security requirements in the DOCSIS Security Specification.
1.3.6.1.4.1.4491.2.1.11.1NodedocsSecMibObjects
1.3.6.1.4.1.4491.2.1.11.1.1NodedocsSecCmtsServerCfg
1.3.6.1.4.1.4491.2.1.11.1.1.1ScalardocsSecCmtsServerCfgTftpOptionsread-writecurrentThis attribute instructs the CMTS to insert the source IP address and/or MAC address of received TFTP packets into the TFTP option fields before forwarding the…
1.3.6.1.4.1.4491.2.1.11.1.1.2ScalardocsSecCmtsServerCfgConfigFileLearningEnableread-writecurrentThis attribute enables and disables Configuration File Learning functionality. If this attribute is set to 'true' the CMTS will respond with Authentication Fai…
1.3.6.1.4.1.4491.2.1.11.1.2NodedocsSecCmtsEncrypt
1.3.6.1.4.1.4491.2.1.11.1.2.1ScalardocsSecCmtsEncryptEncryptAlgPriorityread-writecurrentThis attribute allows for configuration of a prioritized list of encryption algorithms the CMTS will use when selecting the primary SAID encryption algorithm f…
1.3.6.1.4.1.4491.2.1.11.1.3TabledocsSecCmtsCmEaeExclusionTablenot-accessiblecurrentThis object defines a list of CMs or CM groups to exclude from Early Authentication and Encryption (EAE). This object allows overrides to the value of EAE Cont…
1.3.6.1.4.1.4491.2.1.11.1.3.1RowdocsSecCmtsCmEaeExclusionEntrynot-accessiblecurrentThe conceptual row of docsSecCmtsCmEaeExclusion. The CMTS persists all instances of CmtsCmEaeExclusion across reinitializations.
1.3.6.1.4.1.4491.2.1.11.1.3.1.1ColumndocsSecCmtsCmEaeExclusionIdnot-accessiblecurrentThis key uniquely identifies the exclusion MAC address rule.
1.3.6.1.4.1.4491.2.1.11.1.3.1.2ColumndocsSecCmtsCmEaeExclusionMacAddrread-createcurrentThis attribute identifies the CM MAC address. A match is made when a CM MAC address bitwise ANDed with the MacAddrMask attribute equals the value of this attri…
1.3.6.1.4.1.4491.2.1.11.1.3.1.3ColumndocsSecCmtsCmEaeExclusionMacAddrMaskread-createcurrentThis attribute identifies the CM MAC address mask and is used with the MacAddr attribute.
1.3.6.1.4.1.4491.2.1.11.1.3.1.4ColumndocsSecCmtsCmEaeExclusionRowStatusread-createcurrentControls and reflects the status of rows in this table. There is no restriction on changing values in a row of this table while the row is active.
1.3.6.1.4.1.4491.2.1.11.1.4NodedocsSecCmtsSavControl
1.3.6.1.4.1.4491.2.1.11.1.4.1ScalardocsSecCmtsSavControlCmAuthEnableread-writecurrentThis attribute enables or disables Source Address Verification (SAV) for CM configured policies in the SavCmAuth object. If this attribute is set to 'false', t…
1.3.6.1.4.1.4491.2.1.11.1.5TabledocsSecSavCmAuthTablenot-accessiblecurrentThis object defines a read-only set of SAV policies associated with a CM that the CMTS will use in addition to the CMTS verification of an operator assigned IP…
1.3.6.1.4.1.4491.2.1.11.1.5.1RowdocsSecSavCmAuthEntrynot-accessiblecurrentThe conceptual row of docsSecSavCmAuth.
1.3.6.1.4.1.4491.2.1.11.1.5.1.1ColumndocsSecSavCmAuthGrpNameread-onlycurrentThis attribute references the Name attribute of the SavCfgList object of a CM. If the CM signaled group name is not configured in the CMTS, the CMTS ignores th…
1.3.6.1.4.1.4491.2.1.11.1.5.1.2ColumndocsSecSavCmAuthStaticPrefixListIdread-onlycurrentThis attribute identifies the reference to a CMTS created subnet prefix list based on the CM signaled static prefix list TLV elements. The CMTS may reuse this …
1.3.6.1.4.1.4491.2.1.11.1.6TabledocsSecSavCfgListTablenot-accessiblecurrentThis object defines the CMTS configured subnet prefix extension to the SavCmAuth object. This object supports the creation and deletion of multiple instances. …
1.3.6.1.4.1.4491.2.1.11.1.6.1RowdocsSecSavCfgListEntrynot-accessiblecurrentThe conceptual row of docsSecSavCfgList. The CMTS persists all instances of SavCfgList across reinitializations.
1.3.6.1.4.1.4491.2.1.11.1.6.1.1ColumndocsSecSavCfgListNamenot-accessiblecurrentThis attribute is the key that identifies the instance of the SavCmAuth object to which this object extension belongs.
1.3.6.1.4.1.4491.2.1.11.1.6.1.2ColumndocsSecSavCfgListRuleIdnot-accessiblecurrentThis attribute is the key that identifies a particular subnet prefix rule of an instance of this object.
1.3.6.1.4.1.4491.2.1.11.1.6.1.3ColumndocsSecSavCfgListPrefixAddrTyperead-createcurrentThis attribute identifies the IP address type of this subnet prefix rule.
1.3.6.1.4.1.4491.2.1.11.1.6.1.4ColumndocsSecSavCfgListPrefixAddrread-createcurrentThis attribute corresponds to the IP address of this subnet prefix rule in accordance to the PrefixAddrType attribute.
1.3.6.1.4.1.4491.2.1.11.1.6.1.5ColumndocsSecSavCfgListPrefixLenread-createcurrentThis attribute defines the length of the subnet prefix to be matched by this rule.
1.3.6.1.4.1.4491.2.1.11.1.6.1.6ColumndocsSecSavCfgListRowStatusread-createcurrentThe row creation control of this conceptual row. An entry in this table can be set to active only when the following attributes are correctly assigned: PrefixA…
1.3.6.1.4.1.4491.2.1.11.1.7TabledocsSecSavStaticListTablenot-accessiblecurrentThis object defines a subnet prefix extension to the SavCmAuth object based on CM statically signaled subnet prefixes to the CMTS. When a CM signals to the CMT…
1.3.6.1.4.1.4491.2.1.11.1.7.1RowdocsSecSavStaticListEntrynot-accessiblecurrentThe conceptual row of docsSecSavStaticList. The CMTS may persist instances of this object across reinitializations.
1.3.6.1.4.1.4491.2.1.11.1.7.1.1ColumndocsSecSavStaticListIdnot-accessiblecurrentThis key uniquely identifies the index that groups multiple subnet prefix rules. The CMTS assigns this value per CM or may reuse it among multiple CMs that sha…
1.3.6.1.4.1.4491.2.1.11.1.7.1.2ColumndocsSecSavStaticListRuleIdnot-accessiblecurrentThis key identifies a particular static subnet prefix rule of an instance of this object.
1.3.6.1.4.1.4491.2.1.11.1.7.1.3ColumndocsSecSavStaticListPrefixAddrTyperead-onlycurrentThis attribute identifies the IP address type of this subnet prefix rule.
1.3.6.1.4.1.4491.2.1.11.1.7.1.4ColumndocsSecSavStaticListPrefixAddrread-onlycurrentThis attribute corresponds to the IP address of this subnet prefix rule in accordance to the PrefixAddrType attribute.
1.3.6.1.4.1.4491.2.1.11.1.7.1.5ColumndocsSecSavStaticListPrefixLenread-onlycurrentThis attribute defines the length of the subnet prefix to be matched by this rule.
1.3.6.1.4.1.4491.2.1.11.1.8TabledocsSecCmtsCmSavStatsTablenot-accessiblecurrentThis object provides a read-only list of SAV counters for different service theft indications.
1.3.6.1.4.1.4491.2.1.11.1.8.1RowdocsSecCmtsCmSavStatsEntrynot-accessiblecurrentThe conceptual row of docsSecCmtsCmSavStats.
1.3.6.1.4.1.4491.2.1.11.1.8.1.1ColumndocsSecCmtsCmSavStatsSavDiscardsread-onlycurrentThis attribute provides the information about number of dropped upstream packets due to SAV failure.
1.3.6.1.4.1.4491.2.1.11.1.9NodedocsSecCmtsCertificate
1.3.6.1.4.1.4491.2.1.11.1.9.1ScalardocsSecCmtsCertificateCertRevocationMethodread-writecurrentThis attribute identifies which certificate revocation method is to be used by the CMTS to verify the cable modem certificate validity. The certificate revocat…
1.3.6.1.4.1.4491.2.1.11.1.10NodedocsSecCmtsCertRevocationList
1.3.6.1.4.1.4491.2.1.11.1.10.1ScalardocsSecCmtsCertRevocationListUrlread-writecurrentThis attribute contains the URL from where the CMTS will retrieve the CRL. When this attribute is set to a URL value different from the current value, it trigg…
1.3.6.1.4.1.4491.2.1.11.1.10.2ScalardocsSecCmtsCertRevocationListRefreshIntervalread-writecurrentThis attribute contains the refresh interval for the CMTS to retrieve the CRL (referred to in the Url attribute) with the purpose of updating its Certificate R…
1.3.6.1.4.1.4491.2.1.11.1.10.3ScalardocsSecCmtsCertRevocationListLastUpdateread-onlycurrentThis attribute contains the last date and time when the CRL was retrieved by the CMTS. If the CRL has not been updated, then this variable shall have the value…
1.3.6.1.4.1.4491.2.1.11.1.11NodedocsSecCmtsOnlineCertStatusProtocol
1.3.6.1.4.1.4491.2.1.11.1.11.1ScalardocsSecCmtsOnlineCertStatusProtocolUrlread-writecurrentThis attribute contains the URL string to retrieve OCSP information. If the value of this attribute is a zero-length string, the CMTS does not attempt to reque…
1.3.6.1.4.1.4491.2.1.11.1.11.2ScalardocsSecCmtsOnlineCertStatusProtocolSignatureBypassread-writecurrentThis attribute enables or disables signature checking on OCSP response messages. The CMTS persists the value of SignatureBypass across reinitializations.
1.3.6.1.4.1.4491.2.1.11.1.12TabledocsSecCmtsCmBpi2EnforceExclusionTablenot-accessiblecurrentThis object defines a list of CMs or CM groups to exclude from BPI+ enforcement policies configured within the CMTS. This object allows overrides to the value …
1.3.6.1.4.1.4491.2.1.11.1.12.1RowdocsSecCmtsCmBpi2EnforceExclusionEntrynot-accessiblecurrentThe conceptual row of docsSecCmtsCmBpi2EnforceExclusion. The CMTS persists all instances of CmtsCmBpi2EnforceExclusion across reinitializations.
1.3.6.1.4.1.4491.2.1.11.1.12.1.1ColumndocsSecCmtsCmBpi2EnforceExclusionIdnot-accessiblecurrentThis key uniquely identifies the exclusion MAC address rule.
1.3.6.1.4.1.4491.2.1.11.1.12.1.2ColumndocsSecCmtsCmBpi2EnforceExclusionMacAddrread-createcurrentThis attribute identifies the CM MAC address. A match is made when a CM MAC address bitwise ANDed with the MacAddrMask attribute equals the value of this attri…
1.3.6.1.4.1.4491.2.1.11.1.12.1.3ColumndocsSecCmtsCmBpi2EnforceExclusionMacAddrMaskread-createcurrentThis attribute identifies the CM MAC address mask and is used with the MacAddr attribute.
1.3.6.1.4.1.4491.2.1.11.1.12.1.4ColumndocsSecCmtsCmBpi2EnforceExclusionRowStatusread-createcurrentControls and reflects the status of rows in this table. There is no restriction on changing values in a row of this table while the row is active.
1.3.6.1.4.1.4491.2.1.11.1.13NodedocsSecCmSshKeyManagement
1.3.6.1.4.1.4491.2.1.11.1.13.1NodedocsSecCmSshServer
1.3.6.1.4.1.4491.2.1.11.1.13.1.1ScalardocsSecCmSshServerEnabledInterfacesread-onlycurrentThis attribute reports whether SSH server function is enabled in the CM. The CM is required to disable SSH server function by default. The possible values for …
1.3.6.1.4.1.4491.2.1.11.1.13.1.2ScalardocsSecCmSshServerStatusread-onlycurrentThis attribute reports the status of the connection between the CM SSH server and the SSH client.
1.3.6.1.4.1.4491.2.1.11.1.13.1.3ScalardocsSecCmSshServerPublicKeyread-onlycurrentThis attribute is the authorized SSH client public key used by the CM to authenticate the client when the client attempts to set up a CLI SSH connection.
1.3.6.1.4.1.4491.2.1.11.1.13.1.4ScalardocsSecCmSshServerNewConnectionTimeoutread-writecurrentThis attribute is the new SSH connection timeout provisioned on the CM. When this timeout value is reached, the CM sets the Enabled attribute to 'false' and st…
1.3.6.1.4.1.4491.2.1.11.1.13.1.5ScalardocsSecCmSshServerInactivityTimeoutread-writecurrentThis attribute is the SSH inactivity timeout provisioned on the CM. This attribute represents the time at which an established connection is terminated if ther…
1.3.6.1.4.1.4491.2.1.11.1.13.1.6ScalardocsSecCmSshServerSshSourceAddrRestrictionTyperead-writecurrentThe type of internet address associated to the SSH source address restriction.
1.3.6.1.4.1.4491.2.1.11.1.13.1.7ScalardocsSecCmSshServerSshSourceAddrRestrictionread-writecurrentThis optional attribute is the SSH source address restriction provisioned on the CM. When this attribute is not present, the CM enables unrestricted access to …
1.3.6.1.4.1.4491.2.1.11.1.13.1.8ScalardocsSecCmSshServerSshSourcePrefixRestrictionread-writecurrentThis optional attribute is the SSH source address prefix restriction provisioned on the CM. This attribute is a network, address specifier in CIDR notation tha…
1.3.6.1.4.1.4491.2.1.11.1.13.2NodedocsSecCmCdsFileServer
1.3.6.1.4.1.4491.2.1.11.1.13.2.1ScalardocsSecCmCdsFileServerIpAddrTyperead-writecurrentThis attribute indicates the type of the Internet address for IpAddr.
1.3.6.1.4.1.4491.2.1.11.1.13.2.2ScalardocsSecCmCdsFileServerIpAddrread-writecurrentThis attribute is the Internet address of the CDS server in the operator's network.
1.3.6.1.4.1.4491.2.1.11.1.13.2.3ScalardocsSecCmCdsFileServerSshCmCdsDownloadUrlread-writecurrentThis attribute is the URL of the CDS server in the operator's network.
1.3.6.1.4.1.4491.2.1.11.1.13.2.4ScalardocsSecCmCdsFileServerRevocationStatusActionread-writecurrentThis attribute is the action taken by the CM if it does not receive revocation status from the provisioning system server. The possible values for this object …
1.3.6.1.4.1.4491.2.1.11.1.13.3NodedocsSecCmSshCmCds
1.3.6.1.4.1.4491.2.1.11.1.13.3.1TabledocsSecCmPasswordCredentialTablenot-accessiblecurrentThis table contains authorized password credential information for the CM to authenticate SSH Client CLI connections. The CM MUST support creation of new insta…
1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1RowdocsSecCmPasswordCredentialEntrynot-accessiblecurrentThe conceptual row of docsSecCmPasswordCredentialTable.
1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1.1ColumndocsSecCmPasswordCredentialIndexnot-accessiblecurrentThis key attribute represents the unique identifier of an instance of this object.
1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1.2ColumndocsSecCmPasswordCredentialUserIdread-createcurrentThis attribute is the identifier of the user for which the password credential is to be evaluated.
1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1.3ColumndocsSecCmPasswordCredentialPasswordread-createcurrentThis attribute is a string encoded in the [ISO 8859-1] character-set serving as the credential to be evaluated for the user.
1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1.4ColumndocsSecCmPasswordCredentialMacAddrread-createcurrentThis optional attribute is the MAC address assigned to the CM.
1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1.5ColumndocsSecCmPasswordCredentialRowStatusread-createcurrentControls and reflects the status of rows in this table. There is no restriction on changing values in a row of this table while the row is active.
1.3.6.1.4.1.4491.2.1.11.1.13.3.2TabledocsSecCmPublicKeyCredentialTablenot-accessiblecurrentThis table contains authorized RSA Public Key credential information for the CM to authenticate SSH Client CLI connections. The CM MUST support creation of new…
1.3.6.1.4.1.4491.2.1.11.1.13.3.2.1RowdocsSecCmPublicKeyCredentialEntrynot-accessiblecurrentThe conceptual row of docsSecCmPublicKeyCredentialTable.
1.3.6.1.4.1.4491.2.1.11.1.13.3.2.1.1ColumndocsSecCmPublicKeyCredentialIndexnot-accessiblecurrentThis key attribute represents the unique identifier of an instance of this object.
1.3.6.1.4.1.4491.2.1.11.1.13.3.2.1.2ColumndocsSecCmPublicKeyCredentialSshPublicKeyread-createcurrentThis attribute is a string containing a DER-encoded RSA PublicKey or ECDSA public keys in ASN.1 type, as defined in [X.509] and serving as the credential to be…
1.3.6.1.4.1.4491.2.1.11.1.13.3.2.1.3ColumndocsSecCmPublicKeyCredentialMacAddrread-createcurrentThis optional attribute is the MAC address assigned to the CM.
1.3.6.1.4.1.4491.2.1.11.1.13.3.2.1.4ColumndocsSecCmPublicKeyCredentialRowStatusread-createcurrentControls and reflects the status of rows in this table. There is no restriction on changing values in a row of this table while the row is active.
1.3.6.1.4.1.4491.2.1.11.1.13.3.3TabledocsSecCmEccPublicKeyCredentialTablenot-accessibledeprecatedThis table contains authorized ECC Public Key credential information for the CM to authenticate SSH Client CLI connections.
1.3.6.1.4.1.4491.2.1.11.1.13.3.3.1RowdocsSecCmEccPublicKeyCredentialEntrynot-accessibledeprecatedThe conceptual row of docsSecCmEccPublicKeyCredentialTable.
1.3.6.1.4.1.4491.2.1.11.1.13.3.3.1.1ColumndocsSecCmEccPublicKeyCredentialIndexnot-accessibledeprecatedThis key attribute represents the unique identifier of an instance of this object.
1.3.6.1.4.1.4491.2.1.11.1.13.3.3.1.2ColumndocsSecCmEccPublicKeyCredentialEccPublicKeyread-createdeprecatedThis attribute is a string containing ASN.1 DER encoded ECParameters structure as defined in [RFC 3279] and serving as a credential to be evaluated for the use…
1.3.6.1.4.1.4491.2.1.11.1.13.3.3.1.3ColumndocsSecCmEccPublicKeyCredentialMacAddrread-createdeprecatedThis optional attribute is the MAC address assigned to the CM.
1.3.6.1.4.1.4491.2.1.11.1.13.3.3.1.4ColumndocsSecCmEccPublicKeyCredentialRowStatusread-createdeprecatedControls and reflects the status of rows in this table. There is no restriction on changing values in a row of this table while the row is active.
1.3.6.1.4.1.4491.2.1.11.1.13.4NodedocsSecCmSccaServerCfg
1.3.6.1.4.1.4491.2.1.11.1.13.4.1ScalardocsSecCmSccaServerCfgIpAddrTyperead-writecurrentThis attribute indicates the type of the Internet address for IpAddr.
1.3.6.1.4.1.4491.2.1.11.1.13.4.2ScalardocsSecCmSccaServerCfgIpAddrread-writecurrentThis attribute is the Internet address of the CDS server in the operator's network.
1.3.6.1.4.1.4491.2.1.11.1.13.4.3ScalardocsSecCmSccaServerCfgRestApiUrlread-writecurrentThis attribute is the URL of the SCCA REST API to validate the user credentials.
1.3.6.1.4.1.4491.2.1.11.1.13.4.4ScalardocsSecCmSccaServerCfgRevocationStatusActionread-writecurrentThis attribute configures the action taken by the CM if it does not receive revocation status from the HTTPS server. The possible values for this object are li…
1.3.6.1.4.1.4491.2.1.11.2NodedocsSecMibConformance
1.3.6.1.4.1.4491.2.1.11.2.1NodedocsSecMibCompliances
1.3.6.1.4.1.4491.2.1.11.2.1.1CompliancedocsSecCompliancecurrentThe compliance statement for CMTSs that implement the DOCSIS Security MIB.
1.3.6.1.4.1.4491.2.1.11.2.1.2CompliancedocsSecCmCompliancedeprecatedThe compliance statement for CMs that implement the DOCSIS Security MIB.
1.3.6.1.4.1.4491.2.1.11.2.1.3CompliancedocsSecCmSshCompliancecurrentThe compliance statement for CMs that implement SSH Key Management in the DOCSIS Security MIB.
1.3.6.1.4.1.4491.2.1.11.2.2NodedocsSecMibGroups
1.3.6.1.4.1.4491.2.1.11.2.2.1GroupdocsSecGroupcurrentGroup of objects implemented in the CMTS.
1.3.6.1.4.1.4491.2.1.11.2.2.2GroupdocsSecCmGroupdeprecatedGroup of objects deprecated in the CM.
1.3.6.1.4.1.4491.2.1.11.2.2.3GroupdocsSecCmSshGroupcurrentGroup of objects implemented in the CM for Ssh Key Management.
Type Definitions
NameSyntaxStatusDescription
DocsCvcCaCertificateChainOCTET STRING (SIZE (0..8192))currentA degenerate PKCS7 signedData structure that contains the CVC and the CVC CA certificate chain in the certificates field.