SNMP-TLS-TM-MIB
63 objects
The TLS Transport Model MIB Copyright (c) 2010-2011 IETF Trust and the persons identified as authors of the code. All rights reserved. Redistribution and use in source and binary forms, with or without modification, is permitted pursuant to, and subject to the license terms contained in, the Simplified BSD License set forth in Section 4.c of the IETF Trust's Legal Provisions Relating to IETF Documents (http://trustee.ietf.org/license-info).
Imported Objects
| SNMP-FRAMEWORK-MIB | -- RFC 2580 or any update thereof SnmpAdminString |
| SNMP-TARGET-MIB | -- RFC 3411 or any update thereof snmpTargetParamsName snmpTargetAddrName |
| SNMPv2-CONF | -- RFC 2579 or any update thereof MODULE-COMPLIANCE NOTIFICATION-GROUP OBJECT-GROUP |
| SNMPv2-SMI | Counter32 Gauge32 mib-2 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-IDENTITY OBJECT-TYPE snmpDomains Unsigned32 |
| SNMPv2-TC | -- RFC 2578 or any update thereof TEXTUAL-CONVENTION AutonomousType RowStatus StorageType TimeStamp |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.2.1.198 | IdentitysnmpTlstmMIB | The TLS Transport Model MIB Copyright (c) 2010-2011 IETF Trust and the persons identified as authors of the code. All rights reserved. Redistribution and use i… | ||
| 1.3.6.1.2.1.198.0 | NodesnmpTlstmNotifications | |||
| 1.3.6.1.2.1.198.0.1 | NotificationsnmpTlstmServerCertificateUnknown | current | Notification that the server certificate presented by an SNMP over (D)TLS server was invalid because no configured fingerprint or CA was acceptable to validate… | |
| 1.3.6.1.2.1.198.0.2 | NotificationsnmpTlstmServerInvalidCertificate | current | Notification that the server certificate presented by an SNMP over (D)TLS server could not be validated even if the fingerprint or expected validation path was… | |
| 1.3.6.1.2.1.198.1 | NodesnmpTlstmIdentities | |||
| 1.3.6.1.2.1.198.1.1 | NodesnmpTlstmCertToTSNMIdentities | |||
| 1.3.6.1.2.1.198.1.1.1 | IdentitysnmpTlstmCertSpecified | current | Directly specifies the tmSecurityName to be used for this certificate. The value of the tmSecurityName to use is specified in the snmpTlstmCertToTSNData column… | |
| 1.3.6.1.2.1.198.1.1.2 | IdentitysnmpTlstmCertSANRFC822Name | current | Maps a subjectAltName's rfc822Name to a tmSecurityName. The local part of the rfc822Name is passed unaltered but the host-part of the name must be passed in lo… | |
| 1.3.6.1.2.1.198.1.1.3 | IdentitysnmpTlstmCertSANDNSName | current | Maps a subjectAltName's dNSName to a tmSecurityName after first converting it to all lowercase (RFC 5280 does not specify converting to lowercase so this invol… | |
| 1.3.6.1.2.1.198.1.1.4 | IdentitysnmpTlstmCertSANIpAddress | current | Maps a subjectAltName's iPAddress to a tmSecurityName by transforming the binary encoded address as follows: 1) for IPv4, the value is converted into a decimal… | |
| 1.3.6.1.2.1.198.1.1.5 | IdentitysnmpTlstmCertSANAny | current | Maps any of the following fields using the corresponding mapping algorithms: | | Type | Algorithm | | | rfc822Name | snmpTlstmCertSANRFC822Name | | dNSName | s… | |
| 1.3.6.1.2.1.198.1.1.6 | IdentitysnmpTlstmCertCommonName | current | Maps a certificate's CommonName to a tmSecurityName after converting it to a UTF-8 encoding. The usage of CommonNames is deprecated and users are encouraged to… | |
| 1.3.6.1.2.1.198.2 | NodesnmpTlstmObjects | |||
| 1.3.6.1.2.1.198.2.1 | NodesnmpTlstmSession | |||
| 1.3.6.1.2.1.198.2.1.1 | ScalarsnmpTlstmSessionOpens | read-only | current | The number of times an openSession() request has been executed as a (D)TLS client, regardless of whether it succeeded or failed. |
| 1.3.6.1.2.1.198.2.1.2 | ScalarsnmpTlstmSessionClientCloses | read-only | current | The number of times a closeSession() request has been executed as a (D)TLS client, regardless of whether it succeeded or failed. |
| 1.3.6.1.2.1.198.2.1.3 | ScalarsnmpTlstmSessionOpenErrors | read-only | current | The number of times an openSession() request failed to open a session as a (D)TLS client, for any reason. |
| 1.3.6.1.2.1.198.2.1.4 | ScalarsnmpTlstmSessionAccepts | read-only | current | The number of times a (D)TLS server has accepted a new connection from a client and has received at least one SNMP message through it. |
| 1.3.6.1.2.1.198.2.1.5 | ScalarsnmpTlstmSessionServerCloses | read-only | current | The number of times a closeSession() request has been executed as a (D)TLS server, regardless of whether it succeeded or failed. |
| 1.3.6.1.2.1.198.2.1.6 | ScalarsnmpTlstmSessionNoSessions | read-only | current | The number of times an outgoing message was dropped because the session associated with the passed tmStateReference was no longer (or was never) available. |
| 1.3.6.1.2.1.198.2.1.7 | ScalarsnmpTlstmSessionInvalidClientCertificates | read-only | current | The number of times an incoming session was not established on a (D)TLS server because the presented client certificate was invalid. Reasons for invalidation i… |
| 1.3.6.1.2.1.198.2.1.8 | ScalarsnmpTlstmSessionUnknownServerCertificate | read-only | current | The number of times an outgoing session was not established on a (D)TLS client because the server certificate presented by an SNMP over (D)TLS server was inval… |
| 1.3.6.1.2.1.198.2.1.9 | ScalarsnmpTlstmSessionInvalidServerCertificates | read-only | current | The number of times an outgoing session was not established on a (D)TLS client because the server certificate presented by an SNMP over (D)TLS server could not… |
| 1.3.6.1.2.1.198.2.1.10 | ScalarsnmpTlstmSessionInvalidCaches | read-only | current | The number of outgoing messages dropped because the tmStateReference referred to an invalid cache. |
| 1.3.6.1.2.1.198.2.2 | NodesnmpTlstmConfig | |||
| 1.3.6.1.2.1.198.2.2.1 | NodesnmpTlstmCertificateMapping | |||
| 1.3.6.1.2.1.198.2.2.1.1 | ScalarsnmpTlstmCertToTSNCount | read-only | current | A count of the number of entries in the snmpTlstmCertToTSNTable. |
| 1.3.6.1.2.1.198.2.2.1.2 | ScalarsnmpTlstmCertToTSNTableLastChanged | read-only | current | The value of sysUpTime.0 when the snmpTlstmCertToTSNTable was last modified through any means, or 0 if it has not been modified since the command responder was… |
| 1.3.6.1.2.1.198.2.2.1.3 | TablesnmpTlstmCertToTSNTable | not-accessible | current | This table is used by a (D)TLS server to map the (D)TLS client's presented X.509 certificate to a tmSecurityName. On an incoming (D)TLS/SNMP connection, the cl… |
| 1.3.6.1.2.1.198.2.2.1.3.1 | RowsnmpTlstmCertToTSNEntry | not-accessible | current | A row in the snmpTlstmCertToTSNTable that specifies a mapping for an incoming (D)TLS certificate to a tmSecurityName to use for a connection. |
| 1.3.6.1.2.1.198.2.2.1.3.1.1 | ColumnsnmpTlstmCertToTSNID | not-accessible | current | A unique, prioritized index for the given entry. Lower numbers indicate a higher priority. |
| 1.3.6.1.2.1.198.2.2.1.3.1.2 | ColumnsnmpTlstmCertToTSNFingerprint | read-create | current | A cryptographic hash of an X.509 certificate. The results of a successful matching fingerprint to either the trusted CA in the certificate validation path or t… |
| 1.3.6.1.2.1.198.2.2.1.3.1.3 | ColumnsnmpTlstmCertToTSNMapType | read-create | current | Specifies the mapping type for deriving a tmSecurityName from a certificate. Details for mapping of a particular type SHALL be specified in the DESCRIPTION cla… |
| 1.3.6.1.2.1.198.2.2.1.3.1.4 | ColumnsnmpTlstmCertToTSNData | read-create | current | Auxiliary data used as optional configuration information for a given mapping specified by the snmpTlstmCertToTSNMapType column. Only some mapping systems will… |
| 1.3.6.1.2.1.198.2.2.1.3.1.5 | ColumnsnmpTlstmCertToTSNStorageType | read-create | current | The storage type for this conceptual row. Conceptual rows having the value 'permanent' need not allow write-access to any columnar objects in the row. |
| 1.3.6.1.2.1.198.2.2.1.3.1.6 | ColumnsnmpTlstmCertToTSNRowStatus | read-create | current | The status of this conceptual row. This object may be used to create or remove rows from this table. To create a row in this table, an administrator must set t… |
| 1.3.6.1.2.1.198.2.2.1.4 | ScalarsnmpTlstmParamsCount | read-only | current | A count of the number of entries in the snmpTlstmParamsTable. |
| 1.3.6.1.2.1.198.2.2.1.5 | ScalarsnmpTlstmParamsTableLastChanged | read-only | current | The value of sysUpTime.0 when the snmpTlstmParamsTable was last modified through any means, or 0 if it has not been modified since the command responder was st… |
| 1.3.6.1.2.1.198.2.2.1.6 | TablesnmpTlstmParamsTable | not-accessible | current | This table is used by a (D)TLS client when a (D)TLS connection is being set up using an entry in the SNMP-TARGET-MIB. It extends the SNMP-TARGET-MIB's snmpTarg… |
| 1.3.6.1.2.1.198.2.2.1.6.1 | RowsnmpTlstmParamsEntry | not-accessible | current | A conceptual row containing a fingerprint hash of a locally held certificate for a given snmpTargetParamsEntry. The values in this row should be ignored if the… |
| 1.3.6.1.2.1.198.2.2.1.6.1.1 | ColumnsnmpTlstmParamsClientFingerprint | read-create | current | This object stores the hash of the public portion of a locally held X.509 certificate. The X.509 certificate, its public key, and the corresponding private key… |
| 1.3.6.1.2.1.198.2.2.1.6.1.2 | ColumnsnmpTlstmParamsStorageType | read-create | current | The storage type for this conceptual row. Conceptual rows having the value 'permanent' need not allow write-access to any columnar objects in the row. |
| 1.3.6.1.2.1.198.2.2.1.6.1.3 | ColumnsnmpTlstmParamsRowStatus | read-create | current | The status of this conceptual row. This object may be used to create or remove rows from this table. To create a row in this table, an administrator must set t… |
| 1.3.6.1.2.1.198.2.2.1.7 | ScalarsnmpTlstmAddrCount | read-only | current | A count of the number of entries in the snmpTlstmAddrTable. |
| 1.3.6.1.2.1.198.2.2.1.8 | ScalarsnmpTlstmAddrTableLastChanged | read-only | current | The value of sysUpTime.0 when the snmpTlstmAddrTable was last modified through any means, or 0 if it has not been modified since the command responder was star… |
| 1.3.6.1.2.1.198.2.2.1.9 | TablesnmpTlstmAddrTable | not-accessible | current | This table is used by a (D)TLS client when a (D)TLS connection is being set up using an entry in the SNMP-TARGET-MIB. It extends the SNMP-TARGET-MIB's snmpTarg… |
| 1.3.6.1.2.1.198.2.2.1.9.1 | RowsnmpTlstmAddrEntry | not-accessible | current | A conceptual row containing a copy of a certificate's fingerprint for a given snmpTargetAddrEntry. The values in this row should be ignored if the connection t… |
| 1.3.6.1.2.1.198.2.2.1.9.1.1 | ColumnsnmpTlstmAddrServerFingerprint | read-create | current | A cryptographic hash of a public X.509 certificate. This object should store the hash of the public X.509 certificate that the remote server should present dur… |
| 1.3.6.1.2.1.198.2.2.1.9.1.2 | ColumnsnmpTlstmAddrServerIdentity | read-create | current | The reference identity to check against the identity presented by the remote system. |
| 1.3.6.1.2.1.198.2.2.1.9.1.3 | ColumnsnmpTlstmAddrStorageType | read-create | current | The storage type for this conceptual row. Conceptual rows having the value 'permanent' need not allow write-access to any columnar objects in the row. |
| 1.3.6.1.2.1.198.2.2.1.9.1.4 | ColumnsnmpTlstmAddrRowStatus | read-create | current | The status of this conceptual row. This object may be used to create or remove rows from this table. To create a row in this table, an administrator must set t… |
| 1.3.6.1.2.1.198.3 | NodesnmpTlstmConformance | |||
| 1.3.6.1.2.1.198.3.1 | NodesnmpTlstmCompliances | |||
| 1.3.6.1.2.1.198.3.1.1 | CompliancesnmpTlstmCompliance | current | The compliance statement for SNMP engines that support the SNMP-TLS-TM-MIB | |
| 1.3.6.1.2.1.198.3.2 | NodesnmpTlstmGroups | |||
| 1.3.6.1.2.1.198.3.2.1 | GroupsnmpTlstmStatsGroup | current | A collection of objects for maintaining statistical information of an SNMP engine that implements the SNMP TLS Transport Model. | |
| 1.3.6.1.2.1.198.3.2.2 | GroupsnmpTlstmIncomingGroup | current | A collection of objects for maintaining incoming connection certificate mappings to tmSecurityNames of an SNMP engine that implements the SNMP TLS Transport Mo… | |
| 1.3.6.1.2.1.198.3.2.3 | GroupsnmpTlstmOutgoingGroup | current | A collection of objects for maintaining outgoing connection certificates to use when opening connections as a result of SNMP-TARGET-MIB settings. | |
| 1.3.6.1.2.1.198.3.2.4 | GroupsnmpTlstmNotificationGroup | current | Notifications | |
| 1.3.6.1.6.1.8 | IdentitysnmpTLSTCPDomain | current | The SNMP over TLS via TCP transport domain. The corresponding transport address is of type SnmpTLSAddress. The securityName prefix to be associated with the sn… | |
| 1.3.6.1.6.1.9 | IdentitysnmpDTLSUDPDomain | current | The SNMP over DTLS via UDP transport domain. The corresponding transport address is of type SnmpTLSAddress. The securityName prefix to be associated with the s… |
Type Definitions
| Name | Syntax | Status | Description |
|---|---|---|---|
| SnmpTLSAddress | OCTET STRING (SIZE (1..255)) | current | Represents an IPv4 address, an IPv6 address, or a US-ASCII-encoded hostname and port number. An IPv4 address must be in dotted decimal format followed by a colon ':' (US-ASCII character 0x3A) and a decimal port number i… |
| SnmpTLSFingerprint | OCTET STRING (SIZE (0..255)) | current | A fingerprint value that can be used to uniquely reference other data of potentially arbitrary length. An SnmpTLSFingerprint value is composed of a 1-octet hashing algorithm identifier followed by the fingerprint value.… |