CISCO-PKI-MIB

        description
    
Source file
CISCO-PKI-MIB
Last revised
Identity
ciscoPkiMIB
Base OID
1.3.6.1.4.1.9.9.854
Imported Objects
CISCO-SMI ciscoMgmt
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC DisplayString TimeInterval
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-PKI-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-PKI-MIB::ciscoPkiMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-PKI-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-PKI-MIB::ciscoPkiMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (68)
.1.3.6.1.4.1.9.9.854
.1.3.6.1.4.1.9.9.854.1
.1.3.6.1.4.1.9.9.854.2
.1.3.6.1.4.1.9.9.854.2.1
.1.3.6.1.4.1.9.9.854.2.1.1
.1.3.6.1.4.1.9.9.854.2.1.1.1
.1.3.6.1.4.1.9.9.854.2.1.1.1.1
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.10
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.11
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.12
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.13
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.14
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.15
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.16
OctetString
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.3
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.4
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.5
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.6
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.7
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.8
OctetString
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.9
.1.3.6.1.4.1.9.9.854.2.1.2
.1.3.6.1.4.1.9.9.854.2.1.2.1
.1.3.6.1.4.1.9.9.854.2.1.2.1.1
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.1
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.10
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.11
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.12
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.13
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.2
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.3
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.4
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.5
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.6
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.7
OctetString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.8
.1.3.6.1.4.1.9.9.854.2.2
.1.3.6.1.4.1.9.9.854.2.2.1
.1.3.6.1.4.1.9.9.854.2.2.1.1
.1.3.6.1.4.1.9.9.854.2.2.1.1.1
.1.3.6.1.4.1.9.9.854.2.2.1.1.2
.1.3.6.1.4.1.9.9.854.2.2.1.1.3
.1.3.6.1.4.1.9.9.854.2.2.1.1.4
.1.3.6.1.4.1.9.9.854.2.2.1.1.5
.1.3.6.1.4.1.9.9.854.2.2.1.1.6
.1.3.6.1.4.1.9.9.854.2.2.1.1.7
.1.3.6.1.4.1.9.9.854.2.2.1.1.8
.1.3.6.1.4.1.9.9.854.2.2.1.1.9
.1.3.6.1.4.1.9.9.854.2.3
.1.3.6.1.4.1.9.9.854.2.3.1
.1.3.6.1.4.1.9.9.854.2.3.1.1
.1.3.6.1.4.1.9.9.854.2.3.1.1.1
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.1
OctetString
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.2
OctetString
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.3
OctetString
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.4
Unsigned32
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.5
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.6
.1.3.6.1.4.1.9.9.854.2.3.2
.1.3.6.1.4.1.9.9.854.2.3.2.1
.1.3.6.1.4.1.9.9.854.2.3.2.1.1
OctetString
.1.3.6.1.4.1.9.9.854.2.3.2.1.1.1
OctetString
.1.3.6.1.4.1.9.9.854.2.3.2.1.1.2
OctetString
.1.3.6.1.4.1.9.9.854.2.3.2.1.1.3
OctetString
.1.3.6.1.4.1.9.9.854.2.3.2.1.1.4
.1.3.6.1.4.1.9.9.854.3
.1.3.6.1.4.1.9.9.854.3.1
.1.3.6.1.4.1.9.9.854.3.2
Dependencies (4) 4 direct Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Dependency-first compile order
  1. SNMPv2-SMIrfc
  2. CISCO-SMIcisco
  3. SNMPv2-CONFrfc
  4. SNMPv2-TCrfc
  5. CISCO-PKI-MIBciscoselected
Compliance Statements (1)

OID .1.3.6.1.4.1.9.9.854.3.1.1
This is a default module-compliance
containing default object groups.
Required groups
Notifications / Traps (2)
NameOIDDescription
.1.3.6.1.4.1.9.9.854.1.1
When a certificate is installed on the device, notification
will be sent with following information.

a) Certificates Serial number
b) Certificate Issuer-name
c) Certificate Subject name
d) Trustpoint name
e) Type of certificate. (i.e. CA/ID) certificate
f) Certificate Start Date
g) Certificate End Date

Alert will not be sent for RA certificates, trustpool
certificates and self-signed non-persistent certificates.
.1.3.6.1.4.1.9.9.854.1.2
Certificate Expiry alert consists of following
a) Certificate Serial number
b) Certificate Issuer-name
c) Trustpoint name
d) Type of certificate (i.e. CA/ID/SUBCA/RA)
e) Certificate remaining lifetime in seconds.
f) Certificate subject-name

When a certificate is reaching its expiry on the router, a trap
will be sent to SNMP server at regular intervals starting from
60days to till 1week. From 1week onwards daily one trap will be
sent with
following information

a) Certificate Serial number
b) Certificate Issuer-name
c) Trustpoint name
d) Type of certificate (i.e. CA/ID)
e) Certificate remaining lifetime.

Alert will not be sent if trustpoint is configured with
auto-enroll and corresponding shadow certificate/rollover
certificate is present provided, shadow/rollover certificates
start time is same/behind certificate end time.

If shadow/rollover certificate start time is ahead of
certificate end time, alerts will be continued to send because
shadow certificate wont be valid from certificates expiry
time.

Expiry alerts will not be sent for trustpool certificates.