DOCS-SEC-MIB
102 objects
This MIB module contains the management objects for the management of the security requirements in the DOCSIS Security Specification.
Imported Objects
| CLAB-DEF-MIB | clabProjDocsis |
| DOCS-IF3-MIB | -- RFC 4001 docsIf3CmtsCmRegStatusEntry docsIf3CmtsCmRegStatusId |
| INET-ADDRESS-MIB | -- RFC 3411 InetAddressType InetAddress InetAddressPrefixLength |
| SNMP-FRAMEWORK-MIB | -- RFC 2580 SnmpAdminString |
| SNMP-TARGET-MIB | -- RFC 3411 SnmpTagList |
| SNMPv2-CONF | -- RFC 2579 OBJECT-GROUP MODULE-COMPLIANCE |
| SNMPv2-SMI | Counter32 MODULE-IDENTITY OBJECT-TYPE Unsigned32 |
| SNMPv2-TC | -- RFC 2578 TEXTUAL-CONVENTION DateAndTime MacAddress RowStatus TruthValue |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.4491.2.1.11 | IdentitydocsSecMib | This MIB module contains the management objects for the management of the security requirements in the DOCSIS Security Specification. | ||
| 1.3.6.1.4.1.4491.2.1.11.1 | NodedocsSecMibObjects | |||
| 1.3.6.1.4.1.4491.2.1.11.1.1 | NodedocsSecCmtsServerCfg | |||
| 1.3.6.1.4.1.4491.2.1.11.1.1.1 | ScalardocsSecCmtsServerCfgTftpOptions | read-write | current | This attribute instructs the CMTS to insert the source IP address and/or MAC address of received TFTP packets into the TFTP option fields before forwarding the… |
| 1.3.6.1.4.1.4491.2.1.11.1.1.2 | ScalardocsSecCmtsServerCfgConfigFileLearningEnable | read-write | current | This attribute enables and disables Configuration File Learning functionality. If this attribute is set to 'true' the CMTS will respond with Authentication Fai… |
| 1.3.6.1.4.1.4491.2.1.11.1.2 | NodedocsSecCmtsEncrypt | |||
| 1.3.6.1.4.1.4491.2.1.11.1.2.1 | ScalardocsSecCmtsEncryptEncryptAlgPriority | read-write | current | This attribute allows for configuration of a prioritized list of encryption algorithms the CMTS will use when selecting the primary SAID encryption algorithm f… |
| 1.3.6.1.4.1.4491.2.1.11.1.3 | TabledocsSecCmtsCmEaeExclusionTable | not-accessible | current | This object defines a list of CMs or CM groups to exclude from Early Authentication and Encryption (EAE). This object allows overrides to the value of EAE Cont… |
| 1.3.6.1.4.1.4491.2.1.11.1.3.1 | RowdocsSecCmtsCmEaeExclusionEntry | not-accessible | current | The conceptual row of docsSecCmtsCmEaeExclusion. The CMTS persists all instances of CmtsCmEaeExclusion across reinitializations. |
| 1.3.6.1.4.1.4491.2.1.11.1.3.1.1 | ColumndocsSecCmtsCmEaeExclusionId | not-accessible | current | This key uniquely identifies the exclusion MAC address rule. |
| 1.3.6.1.4.1.4491.2.1.11.1.3.1.2 | ColumndocsSecCmtsCmEaeExclusionMacAddr | read-create | current | This attribute identifies the CM MAC address. A match is made when a CM MAC address bitwise ANDed with the MacAddrMask attribute equals the value of this attri… |
| 1.3.6.1.4.1.4491.2.1.11.1.3.1.3 | ColumndocsSecCmtsCmEaeExclusionMacAddrMask | read-create | current | This attribute identifies the CM MAC address mask and is used with the MacAddr attribute. |
| 1.3.6.1.4.1.4491.2.1.11.1.3.1.4 | ColumndocsSecCmtsCmEaeExclusionRowStatus | read-create | current | Controls and reflects the status of rows in this table. There is no restriction on changing values in a row of this table while the row is active. |
| 1.3.6.1.4.1.4491.2.1.11.1.4 | NodedocsSecCmtsSavControl | |||
| 1.3.6.1.4.1.4491.2.1.11.1.4.1 | ScalardocsSecCmtsSavControlCmAuthEnable | read-write | current | This attribute enables or disables Source Address Verification (SAV) for CM configured policies in the SavCmAuth object. If this attribute is set to 'false', t… |
| 1.3.6.1.4.1.4491.2.1.11.1.5 | TabledocsSecSavCmAuthTable | not-accessible | current | This object defines a read-only set of SAV policies associated with a CM that the CMTS will use in addition to the CMTS verification of an operator assigned IP… |
| 1.3.6.1.4.1.4491.2.1.11.1.5.1 | RowdocsSecSavCmAuthEntry | not-accessible | current | The conceptual row of docsSecSavCmAuth. |
| 1.3.6.1.4.1.4491.2.1.11.1.5.1.1 | ColumndocsSecSavCmAuthGrpName | read-only | current | This attribute references the Name attribute of the SavCfgList object of a CM. If the CM signaled group name is not configured in the CMTS, the CMTS ignores th… |
| 1.3.6.1.4.1.4491.2.1.11.1.5.1.2 | ColumndocsSecSavCmAuthStaticPrefixListId | read-only | current | This attribute identifies the reference to a CMTS created subnet prefix list based on the CM signaled static prefix list TLV elements. The CMTS may reuse this … |
| 1.3.6.1.4.1.4491.2.1.11.1.6 | TabledocsSecSavCfgListTable | not-accessible | current | This object defines the CMTS configured subnet prefix extension to the SavCmAuth object. This object supports the creation and deletion of multiple instances. … |
| 1.3.6.1.4.1.4491.2.1.11.1.6.1 | RowdocsSecSavCfgListEntry | not-accessible | current | The conceptual row of docsSecSavCfgList. The CMTS persists all instances of SavCfgList across reinitializations. |
| 1.3.6.1.4.1.4491.2.1.11.1.6.1.1 | ColumndocsSecSavCfgListName | not-accessible | current | This attribute is the key that identifies the instance of the SavCmAuth object to which this object extension belongs. |
| 1.3.6.1.4.1.4491.2.1.11.1.6.1.2 | ColumndocsSecSavCfgListRuleId | not-accessible | current | This attribute is the key that identifies a particular subnet prefix rule of an instance of this object. |
| 1.3.6.1.4.1.4491.2.1.11.1.6.1.3 | ColumndocsSecSavCfgListPrefixAddrType | read-create | current | This attribute identifies the IP address type of this subnet prefix rule. |
| 1.3.6.1.4.1.4491.2.1.11.1.6.1.4 | ColumndocsSecSavCfgListPrefixAddr | read-create | current | This attribute corresponds to the IP address of this subnet prefix rule in accordance to the PrefixAddrType attribute. |
| 1.3.6.1.4.1.4491.2.1.11.1.6.1.5 | ColumndocsSecSavCfgListPrefixLen | read-create | current | This attribute defines the length of the subnet prefix to be matched by this rule. |
| 1.3.6.1.4.1.4491.2.1.11.1.6.1.6 | ColumndocsSecSavCfgListRowStatus | read-create | current | The row creation control of this conceptual row. An entry in this table can be set to active only when the following attributes are correctly assigned: PrefixA… |
| 1.3.6.1.4.1.4491.2.1.11.1.7 | TabledocsSecSavStaticListTable | not-accessible | current | This object defines a subnet prefix extension to the SavCmAuth object based on CM statically signaled subnet prefixes to the CMTS. When a CM signals to the CMT… |
| 1.3.6.1.4.1.4491.2.1.11.1.7.1 | RowdocsSecSavStaticListEntry | not-accessible | current | The conceptual row of docsSecSavStaticList. The CMTS may persist instances of this object across reinitializations. |
| 1.3.6.1.4.1.4491.2.1.11.1.7.1.1 | ColumndocsSecSavStaticListId | not-accessible | current | This key uniquely identifies the index that groups multiple subnet prefix rules. The CMTS assigns this value per CM or may reuse it among multiple CMs that sha… |
| 1.3.6.1.4.1.4491.2.1.11.1.7.1.2 | ColumndocsSecSavStaticListRuleId | not-accessible | current | This key identifies a particular static subnet prefix rule of an instance of this object. |
| 1.3.6.1.4.1.4491.2.1.11.1.7.1.3 | ColumndocsSecSavStaticListPrefixAddrType | read-only | current | This attribute identifies the IP address type of this subnet prefix rule. |
| 1.3.6.1.4.1.4491.2.1.11.1.7.1.4 | ColumndocsSecSavStaticListPrefixAddr | read-only | current | This attribute corresponds to the IP address of this subnet prefix rule in accordance to the PrefixAddrType attribute. |
| 1.3.6.1.4.1.4491.2.1.11.1.7.1.5 | ColumndocsSecSavStaticListPrefixLen | read-only | current | This attribute defines the length of the subnet prefix to be matched by this rule. |
| 1.3.6.1.4.1.4491.2.1.11.1.8 | TabledocsSecCmtsCmSavStatsTable | not-accessible | current | This object provides a read-only list of SAV counters for different service theft indications. |
| 1.3.6.1.4.1.4491.2.1.11.1.8.1 | RowdocsSecCmtsCmSavStatsEntry | not-accessible | current | The conceptual row of docsSecCmtsCmSavStats. |
| 1.3.6.1.4.1.4491.2.1.11.1.8.1.1 | ColumndocsSecCmtsCmSavStatsSavDiscards | read-only | current | This attribute provides the information about number of dropped upstream packets due to SAV failure. |
| 1.3.6.1.4.1.4491.2.1.11.1.9 | NodedocsSecCmtsCertificate | |||
| 1.3.6.1.4.1.4491.2.1.11.1.9.1 | ScalardocsSecCmtsCertificateCertRevocationMethod | read-write | current | This attribute identifies which certificate revocation method is to be used by the CMTS to verify the cable modem certificate validity. The certificate revocat… |
| 1.3.6.1.4.1.4491.2.1.11.1.10 | NodedocsSecCmtsCertRevocationList | |||
| 1.3.6.1.4.1.4491.2.1.11.1.10.1 | ScalardocsSecCmtsCertRevocationListUrl | read-write | current | This attribute contains the URL from where the CMTS will retrieve the CRL. When this attribute is set to a URL value different from the current value, it trigg… |
| 1.3.6.1.4.1.4491.2.1.11.1.10.2 | ScalardocsSecCmtsCertRevocationListRefreshInterval | read-write | current | This attribute contains the refresh interval for the CMTS to retrieve the CRL (referred to in the Url attribute) with the purpose of updating its Certificate R… |
| 1.3.6.1.4.1.4491.2.1.11.1.10.3 | ScalardocsSecCmtsCertRevocationListLastUpdate | read-only | current | This attribute contains the last date and time when the CRL was retrieved by the CMTS. If the CRL has not been updated, then this variable shall have the value… |
| 1.3.6.1.4.1.4491.2.1.11.1.11 | NodedocsSecCmtsOnlineCertStatusProtocol | |||
| 1.3.6.1.4.1.4491.2.1.11.1.11.1 | ScalardocsSecCmtsOnlineCertStatusProtocolUrl | read-write | current | This attribute contains the URL string to retrieve OCSP information. If the value of this attribute is a zero-length string, the CMTS does not attempt to reque… |
| 1.3.6.1.4.1.4491.2.1.11.1.11.2 | ScalardocsSecCmtsOnlineCertStatusProtocolSignatureBypass | read-write | current | This attribute enables or disables signature checking on OCSP response messages. The CMTS persists the value of SignatureBypass across reinitializations. |
| 1.3.6.1.4.1.4491.2.1.11.1.12 | TabledocsSecCmtsCmBpi2EnforceExclusionTable | not-accessible | current | This object defines a list of CMs or CM groups to exclude from BPI+ enforcement policies configured within the CMTS. This object allows overrides to the value … |
| 1.3.6.1.4.1.4491.2.1.11.1.12.1 | RowdocsSecCmtsCmBpi2EnforceExclusionEntry | not-accessible | current | The conceptual row of docsSecCmtsCmBpi2EnforceExclusion. The CMTS persists all instances of CmtsCmBpi2EnforceExclusion across reinitializations. |
| 1.3.6.1.4.1.4491.2.1.11.1.12.1.1 | ColumndocsSecCmtsCmBpi2EnforceExclusionId | not-accessible | current | This key uniquely identifies the exclusion MAC address rule. |
| 1.3.6.1.4.1.4491.2.1.11.1.12.1.2 | ColumndocsSecCmtsCmBpi2EnforceExclusionMacAddr | read-create | current | This attribute identifies the CM MAC address. A match is made when a CM MAC address bitwise ANDed with the MacAddrMask attribute equals the value of this attri… |
| 1.3.6.1.4.1.4491.2.1.11.1.12.1.3 | ColumndocsSecCmtsCmBpi2EnforceExclusionMacAddrMask | read-create | current | This attribute identifies the CM MAC address mask and is used with the MacAddr attribute. |
| 1.3.6.1.4.1.4491.2.1.11.1.12.1.4 | ColumndocsSecCmtsCmBpi2EnforceExclusionRowStatus | read-create | current | Controls and reflects the status of rows in this table. There is no restriction on changing values in a row of this table while the row is active. |
| 1.3.6.1.4.1.4491.2.1.11.1.13 | NodedocsSecCmSshKeyManagement | |||
| 1.3.6.1.4.1.4491.2.1.11.1.13.1 | NodedocsSecCmSshServer | |||
| 1.3.6.1.4.1.4491.2.1.11.1.13.1.1 | ScalardocsSecCmSshServerEnabledInterfaces | read-only | current | This attribute reports whether SSH server function is enabled in the CM. The CM is required to disable SSH server function by default. The possible values for … |
| 1.3.6.1.4.1.4491.2.1.11.1.13.1.2 | ScalardocsSecCmSshServerStatus | read-only | current | This attribute reports the status of the connection between the CM SSH server and the SSH client. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.1.3 | ScalardocsSecCmSshServerPublicKey | read-only | current | This attribute is the authorized SSH client public key used by the CM to authenticate the client when the client attempts to set up a CLI SSH connection. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.1.4 | ScalardocsSecCmSshServerNewConnectionTimeout | read-write | current | This attribute is the new SSH connection timeout provisioned on the CM. When this timeout value is reached, the CM sets the Enabled attribute to 'false' and st… |
| 1.3.6.1.4.1.4491.2.1.11.1.13.1.5 | ScalardocsSecCmSshServerInactivityTimeout | read-write | current | This attribute is the SSH inactivity timeout provisioned on the CM. This attribute represents the time at which an established connection is terminated if ther… |
| 1.3.6.1.4.1.4491.2.1.11.1.13.1.6 | ScalardocsSecCmSshServerSshSourceAddrRestrictionType | read-write | current | The type of internet address associated to the SSH source address restriction. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.1.7 | ScalardocsSecCmSshServerSshSourceAddrRestriction | read-write | current | This optional attribute is the SSH source address restriction provisioned on the CM. When this attribute is not present, the CM enables unrestricted access to … |
| 1.3.6.1.4.1.4491.2.1.11.1.13.1.8 | ScalardocsSecCmSshServerSshSourcePrefixRestriction | read-write | current | This optional attribute is the SSH source address prefix restriction provisioned on the CM. This attribute is a network, address specifier in CIDR notation tha… |
| 1.3.6.1.4.1.4491.2.1.11.1.13.2 | NodedocsSecCmCdsFileServer | |||
| 1.3.6.1.4.1.4491.2.1.11.1.13.2.1 | ScalardocsSecCmCdsFileServerIpAddrType | read-write | current | This attribute indicates the type of the Internet address for IpAddr. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.2.2 | ScalardocsSecCmCdsFileServerIpAddr | read-write | current | This attribute is the Internet address of the CDS server in the operator's network. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.2.3 | ScalardocsSecCmCdsFileServerSshCmCdsDownloadUrl | read-write | current | This attribute is the URL of the CDS server in the operator's network. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.2.4 | ScalardocsSecCmCdsFileServerRevocationStatusAction | read-write | current | This attribute is the action taken by the CM if it does not receive revocation status from the provisioning system server. The possible values for this object … |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3 | NodedocsSecCmSshCmCds | |||
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.1 | TabledocsSecCmPasswordCredentialTable | not-accessible | current | This table contains authorized password credential information for the CM to authenticate SSH Client CLI connections. The CM MUST support creation of new insta… |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1 | RowdocsSecCmPasswordCredentialEntry | not-accessible | current | The conceptual row of docsSecCmPasswordCredentialTable. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1.1 | ColumndocsSecCmPasswordCredentialIndex | not-accessible | current | This key attribute represents the unique identifier of an instance of this object. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1.2 | ColumndocsSecCmPasswordCredentialUserId | read-create | current | This attribute is the identifier of the user for which the password credential is to be evaluated. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1.3 | ColumndocsSecCmPasswordCredentialPassword | read-create | current | This attribute is a string encoded in the [ISO 8859-1] character-set serving as the credential to be evaluated for the user. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1.4 | ColumndocsSecCmPasswordCredentialMacAddr | read-create | current | This optional attribute is the MAC address assigned to the CM. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.1.1.5 | ColumndocsSecCmPasswordCredentialRowStatus | read-create | current | Controls and reflects the status of rows in this table. There is no restriction on changing values in a row of this table while the row is active. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.2 | TabledocsSecCmPublicKeyCredentialTable | not-accessible | current | This table contains authorized RSA Public Key credential information for the CM to authenticate SSH Client CLI connections. The CM MUST support creation of new… |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.2.1 | RowdocsSecCmPublicKeyCredentialEntry | not-accessible | current | The conceptual row of docsSecCmPublicKeyCredentialTable. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.2.1.1 | ColumndocsSecCmPublicKeyCredentialIndex | not-accessible | current | This key attribute represents the unique identifier of an instance of this object. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.2.1.2 | ColumndocsSecCmPublicKeyCredentialSshPublicKey | read-create | current | This attribute is a string containing a DER-encoded RSA PublicKey or ECDSA public keys in ASN.1 type, as defined in [X.509] and serving as the credential to be… |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.2.1.3 | ColumndocsSecCmPublicKeyCredentialMacAddr | read-create | current | This optional attribute is the MAC address assigned to the CM. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.2.1.4 | ColumndocsSecCmPublicKeyCredentialRowStatus | read-create | current | Controls and reflects the status of rows in this table. There is no restriction on changing values in a row of this table while the row is active. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.3 | TabledocsSecCmEccPublicKeyCredentialTable | not-accessible | deprecated | This table contains authorized ECC Public Key credential information for the CM to authenticate SSH Client CLI connections. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.3.1 | RowdocsSecCmEccPublicKeyCredentialEntry | not-accessible | deprecated | The conceptual row of docsSecCmEccPublicKeyCredentialTable. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.3.1.1 | ColumndocsSecCmEccPublicKeyCredentialIndex | not-accessible | deprecated | This key attribute represents the unique identifier of an instance of this object. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.3.1.2 | ColumndocsSecCmEccPublicKeyCredentialEccPublicKey | read-create | deprecated | This attribute is a string containing ASN.1 DER encoded ECParameters structure as defined in [RFC 3279] and serving as a credential to be evaluated for the use… |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.3.1.3 | ColumndocsSecCmEccPublicKeyCredentialMacAddr | read-create | deprecated | This optional attribute is the MAC address assigned to the CM. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.3.3.1.4 | ColumndocsSecCmEccPublicKeyCredentialRowStatus | read-create | deprecated | Controls and reflects the status of rows in this table. There is no restriction on changing values in a row of this table while the row is active. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.4 | NodedocsSecCmSccaServerCfg | |||
| 1.3.6.1.4.1.4491.2.1.11.1.13.4.1 | ScalardocsSecCmSccaServerCfgIpAddrType | read-write | current | This attribute indicates the type of the Internet address for IpAddr. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.4.2 | ScalardocsSecCmSccaServerCfgIpAddr | read-write | current | This attribute is the Internet address of the CDS server in the operator's network. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.4.3 | ScalardocsSecCmSccaServerCfgRestApiUrl | read-write | current | This attribute is the URL of the SCCA REST API to validate the user credentials. |
| 1.3.6.1.4.1.4491.2.1.11.1.13.4.4 | ScalardocsSecCmSccaServerCfgRevocationStatusAction | read-write | current | This attribute configures the action taken by the CM if it does not receive revocation status from the HTTPS server. The possible values for this object are li… |
| 1.3.6.1.4.1.4491.2.1.11.2 | NodedocsSecMibConformance | |||
| 1.3.6.1.4.1.4491.2.1.11.2.1 | NodedocsSecMibCompliances | |||
| 1.3.6.1.4.1.4491.2.1.11.2.1.1 | CompliancedocsSecCompliance | current | The compliance statement for CMTSs that implement the DOCSIS Security MIB. | |
| 1.3.6.1.4.1.4491.2.1.11.2.1.2 | CompliancedocsSecCmCompliance | deprecated | The compliance statement for CMs that implement the DOCSIS Security MIB. | |
| 1.3.6.1.4.1.4491.2.1.11.2.1.3 | CompliancedocsSecCmSshCompliance | current | The compliance statement for CMs that implement SSH Key Management in the DOCSIS Security MIB. | |
| 1.3.6.1.4.1.4491.2.1.11.2.2 | NodedocsSecMibGroups | |||
| 1.3.6.1.4.1.4491.2.1.11.2.2.1 | GroupdocsSecGroup | current | Group of objects implemented in the CMTS. | |
| 1.3.6.1.4.1.4491.2.1.11.2.2.2 | GroupdocsSecCmGroup | deprecated | Group of objects deprecated in the CM. | |
| 1.3.6.1.4.1.4491.2.1.11.2.2.3 | GroupdocsSecCmSshGroup | current | Group of objects implemented in the CM for Ssh Key Management. |
Type Definitions
| Name | Syntax | Status | Description |
|---|---|---|---|
| DocsCvcCaCertificateChain | OCTET STRING (SIZE (0..8192)) | current | A degenerate PKCS7 signedData structure that contains the CVC and the CVC CA certificate chain in the certificates field. |