FEC-CERT-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
5
Rows
5
Columns
62
.0.2 · 1 row entry · 6 columns
Uses the bintec variant from /opt/observium/mibs/bintec.
Command help
Walk ipsecPublicKeyTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'FEC-CERT-MIB' -M '/opt/observium/mibs/bintec:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'FEC-CERT-MIB::ipsecPublicKeyTable'
This table contains the list of public key pairs and ID's used
with IPSec.
ipsecPubKeyEntry row .0.2.1
This object contains a key pair for a certain public key
algorithm and the ids used together with this key.
Column Syntax OID
A unique index for this entry.
Integer32
Type Constraints:
range: -2147483648..2147483647
.0.2.1.1
An optional description for this key.
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.2.1.2
This object specifies the algorithm for which the key is used.
Possible values:
rsa(2), -- The RSA encryption algorithm
dsa(3), -- The digital signature algorithm
delete(15) -- Mark this entry for deletion.
Enumerationr/w
Enumerated Values:
2rsa
3dsa
15delete
.0.2.1.3
The size of the public and private keys in bits.
bitsInteger32r/w
Type Constraints:
range: -2147483648..2147483647
.0.2.1.4
The RSA public exponent of the key. (undefined for DSA)
Integer32r/w
Type Constraints:
range: -2147483648..2147483647
.0.2.1.5
This object specifies the state of the Key.
Possible values:
generating(1), -- Key generation is in progress
complete(2), -- Key generation is complete
error(3) -- Key generation terminated with an error.
Enumeration
Enumerated Values:
1generating
2complete
3error
.0.2.1.6
.0.33.2 · 1 row entry · 4 columns
Uses the bintec variant from /opt/observium/mibs/bintec.
Command help
Walk certServerTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'FEC-CERT-MIB' -M '/opt/observium/mibs/bintec:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'FEC-CERT-MIB::certServerTable'
The certServerTable contains the list of certificate servers
used for certificate and crl requests.
certServerEntry row .0.33.2.1
A certificate server entry defines the name of a certificate
server together with the protocols used to access it.
Column Syntax OID
This object specifies the name of a certificate server.
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.2.1.1
This object specifies the url used for accessing the
certificate server. Syntax:
[<scheme>:][//[<user>[:<password>]@]<host>[:<port>]]/[<path>]
example: ldap://myname:mypass@ldap.ca.com:389/ .
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.2.1.2
This object specifies the preference of this server
with respect to the others. Servers with lower priority
are accessed prior to others.
Integer32r/w
Type Constraints:
range: -2147483648..2147483647
.0.33.2.1.3
This object specifies the type of the entry and is used to
delete it.
Enumerationr/w
Enumerated Values:
1delete
2server
.0.33.2.1.4

certTable

table
.0.33.3 · 1 row entry · 20 columns
Uses the bintec variant from /opt/observium/mibs/bintec.
Command help
Walk certTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'FEC-CERT-MIB' -M '/opt/observium/mibs/bintec:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'FEC-CERT-MIB::certTable'
The certTable contains the list of certificates known to the 
system.
This includes own certificates, peer certificates, 
root CA certificates and intermediate CA certificates, 
dynamically loaded as well as manually configured.
certEntry row .0.33.3.1
A certEntry contains the description of a certificate.
Indexes
Column Syntax OID
A unique index of this certificate entry.
Dynamically loaded certificates are assigned negative indexes.
Integer32
Type Constraints:
range: -2147483648..2147483647
.0.33.3.1.1
This object specifies the name of the X.509 Certificate.
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.3.1.2
This object determines if the entry specifies a globally
trusted root certificate.
Possible Values:
true(1), -- Globally trusted root certificate
false(2) -- not globally trusted root certificate.
Enumerationr/w
Enumerated Values:
1true
2false
.0.33.3.1.3
This object specifies if the certificate is trusted without any
further validity check.
Possible Values:
true(1), -- Disable any validity checks
false(2) -- Run validity checks as far as configured
-- otherwise.
Enumerationr/w
Enumerated Values:
1true
2false
.0.33.3.1.4
This object determines how CRL checking is performed
for this certificate.
Possible Values:
true(1), -- do not check for certificate revocation
-- lists for this CA (no meaning for non-CA
-- certificates)
f…
Enumerationr/w
Enumerated Values:
1true
2false
3auto
4inherit
.0.33.3.1.5
This object shows the serial number of the certificate.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.3.1.6
This object shows the subject name of the certificate.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.3.1.7
This object shows the subject alternative names of the
certificate.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.3.1.8
This object shows the name of the certificate authority
which issued the certificate.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.3.1.9
This object shows the alternative names of the certificate
authority which issued the certificate.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.3.1.10
This object shows the properties of the public key
certified in this certificate.
These are the algorithm for which the key is used
and its length.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.3.1.12
This object shows the key id as contained in the extensions
of the certificate, if any.
OctetString .0.33.3.1.13
This object shows the index of the private key from the
ipsecPublicKeyTable corresponding to the public key
contained in this certificate.
If this object is zero, there is no private key available
for this certificate.
Integer32
Type Constraints:
range: -2147483648..2147483647
.0.33.3.1.14
This object shows the beginning of the validity period
of the certificate (GMT).
.0.33.3.1.15
This object shows the end of the validity period
of the certificate (GMT).
.0.33.3.1.16
This object shows the key usage flags contained
in the extensions of the certificate, if any.
The flags are:
EncipherOnly 0x00000001
CrlSign 0x00000002
KeyCertSign 0x00000004
KeyAgreement …
.0.33.3.1.17
This object shows the fingerprint of the certificate
computed as an MD5 hash of the DER encoded binary certificate.
Compare this object against an externally retrieved MD5
fingerprint (e.g. published on a CA's web site)…
OctetString .0.33.3.1.24
This object shows the fingerprint of the certificate
computed as an SHA1 hash of the DER encoded binary certificate.
Compare this object against an externally retrieved SHA1
fingerprint (e.g. published on a CA's web sit…
OctetString .0.33.3.1.25
This object shows the instance which created the certificate.
Enumeration
Enumerated Values:
1config
2ike
3ldap
4http
.0.33.3.1.26
The remaining up-to-dateness of the certificate in percent.
0 means certificate is no more valid.
100 means certificate is not yet valid, but will be valid
in future.
This variable is updated every 24 hours.
Integer32
Constraints:
range: 0-100
.0.33.3.1.27
.0.33.6 · 1 row entry · 9 columns
Uses the bintec variant from /opt/observium/mibs/bintec.
Command help
Walk certRevListTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'FEC-CERT-MIB' -M '/opt/observium/mibs/bintec:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'FEC-CERT-MIB::certRevListTable'
The certRevListTable contains the dynamic list of certificate
revocation lists currently cached by the system.
certRevListEntry row .0.33.6.1
This object describes a certificate revocation list (CRL)
currently in the systems dynamic CRL cache.
Column Syntax OID
A unique index of this CRL.
Integer32
Type Constraints:
range: -2147483648..2147483647
.0.33.6.1.1
This object specifies the name of the certificate
revocation list.
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.6.1.2
The name of the certificate authority which issued this CRL.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.6.1.3
The alternative names of the certificate authority which issued
this CRL.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.6.1.4
The serial number of the CRL.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.6.1.5
The number of certificates contained in the CRL defined by this
entry.
Integer32
Type Constraints:
range: -2147483648..2147483647
.0.33.6.1.7
The instance which created this crl.
Enumeration
Enumerated Values:
1config
2ike
3ldap
4http
.0.33.6.1.8
The beginning of the validity period of CRL (GMT).
.0.33.6.1.9
The end of the validity period of the CRL (GMT).
.0.33.6.1.10
.0.33.7 · 1 row entry · 23 columns
Uses the bintec variant from /opt/observium/mibs/bintec.
Command help
Walk certMgmtTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'FEC-CERT-MIB' -M '/opt/observium/mibs/bintec:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'FEC-CERT-MIB::certMgmtTable'
The certMgmtTable provides MIB access to the machines
certificate management functions. These are certificate
download/upload, creation ofd certificate requests and
automatic certificate enrollment.
certMgmtEntry row .0.33.7.1
This object specifies a task in the systems certMgmtTable.
The system automatically deletes all tasks which have been
finished except the most recent one.
Indexes
Column Syntax OID
A unique index for this entry.
Integer32
Type Constraints:
range: -2147483648..2147483647
.0.33.7.1.1
The task to perform for this entry.
Possible values:
getca-scep(1), -- Retrieve CA certificate via SCEP
enroll-scep(2), -- Enroll using SCEP
enroll-manual(3), -- Do a manual enrollment
delete(8) -- Cancel the task …
Enumerationr/w
Enumerated Values:
1getca-scep
2enroll-scep
3enroll-manual
8delete
.0.33.7.1.2
The url to access for the task.
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.7.1.3
The name of the resulting certificate (for certificate
retrieval tasks) or the name of the certificate to use
(for certificate export tasks.
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.7.1.4
The subject name to include into the certificate request.
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.7.1.5
The subject alternative name to include into the certificate
request (optional).
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.7.1.6
A second subject alternative name (optional).
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.7.1.7
A third subject alternative name (optional).
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.7.1.8
The index of the key in the ipsecPublicKeyTable to use for
certificate enrollment.
Integer32r/w
Type Constraints:
range: -2147483648..2147483647
.0.33.7.1.9
The index of the CA certificate to use (from the certTable).
Integer32r/w
Type Constraints:
range: -2147483648..2147483647
.0.33.7.1.10
The domain for which the CA certificate is to be received
(getca_scep command only).
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.7.1.11
The password (SCEP: challenge password, CMP: <ref-no>:<psk>.
SNMPv2-TCDisplayStringr/w
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.0.33.7.1.12
Determines if pending requests should be saved permanently
after each try and results should be saved permanently after
finish.
Enumerationr/w
Enumerated Values:
1true
2false
.0.33.7.1.13
The interval (in seconds) between polls.
Integer32r/w
Constraints:
range: 5-86400
.0.33.7.1.14
The maximum number of polls performed. A value of -1 means
forever, a value of 0 disables polling, i.e. the task is
cancelled if the initial result is delayed.
Integer32r/w
Constraints:
range: -1-32767
.0.33.7.1.15
The number of polls already performed.
Integer32
Type Constraints:
range: -2147483648..2147483647
.0.33.7.1.16
The state of the task specified by this entry.
Enumeration
Enumerated Values:
1done
2error
3running
4delayed
5polling
6notreached
.0.33.7.1.17
The index of the Registration Authority's (RA) certificate to
use for signing purposes (from the certTable).
Integer32r/w
Type Constraints:
range: -2147483648..2147483647
.0.33.7.1.18
The index of the Registration Authority's (RA) certificate to
use for encryption purposes (from the certTable).
Integer32r/w
Type Constraints:
range: -2147483648..2147483647
.0.33.7.1.19
The key length in bits used in requests for certificate enrollment.
Integer32r/w
Type Constraints:
range: -2147483648..2147483647
.0.33.7.1.20
This object holds the fingerprint of the CA certificate
computed as an SHA1 or MD5 hash.
This object is compared against an externally retrieved
SHA1 / MD5 fingerprint (e.g. published on a CA's web site) to
assure the a…
OctetStringr/w .0.33.7.1.21
This object determines how CRL checking is set for
certificates retrieved during certificate enrollment.
Possible Values:
true(1), -- do not check for certificate revocation
-- lists for this CA (no meaning for n…
Enumerationr/w
Enumerated Values:
1true
2false
3auto
4inherit
.0.33.7.1.22
Flag whether certificate management task is waiting or
starts immediately.
Use this flag to create complex tasks in multiple steps:
First create task with certMgmtAction set to 'wait'. After
task is completely build, se…
Enumerationr/w
Enumerated Values:
1wait
2go
.0.33.7.1.23