ONEACCESS-GDOI-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
3
Rows
3
Columns
18
.1.3.6.1.4.1.13191.10.3.4.1224.1.1 · 1 row entry · 3 columns
A table of information regarding GDOI Groups in use on
the network device being queried.
oacGdoiGroupEntry entry .1.3.6.1.4.1.13191.10.3.4.1224.1.1.1
An entry containing GDOI Group information, uniquely
identified by the GDOI Group ID.
Indexes
oacGdoiGroupName
Column Syntax OID
oacGdoiGroupName
The string-readable name configured for or given to a GDOI
Group.
SNMPv2-TCDisplayString
Textual Convention: SNMPv2-TCDisplayString OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.13191.10.3.4.1224.1.1.1.1
oacGdoiGroupIdType
The Identification Type Value used to parse a GDOI Group ID.
The GDOI RFC 3547 defines the types that can be used as a
GDOI Group ID, and RFC 4306 defines all valid types that can
be used as an identifier.
OacGdoiIdentificationType
Textual Convention: OacGdoiIdentificationType Enumeration
Type Values:
1keyID
2ipv4
.1.3.6.1.4.1.13191.10.3.4.1224.1.1.1.2
oacGdoiGroupIdValue
The value of a Group ID with its type indicated by the
oacGdoiGroupIdType. Use the oacGdoiGroupIdType to parse the
Group ID correctly. This Group ID value is sent as the
'Identification Data' field of the Identificati…
OacGdoiIdentificationValue
Textual Convention: OacGdoiIdentificationValue OctetString
Type Constraints:
range: 0..16
.1.3.6.1.4.1.13191.10.3.4.1224.1.1.1.3
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2 · 1 row entry · 5 columns
A table of information regarding GDOI Group Members (GMs)
locally configured on the network device being queried.  Note
that Local Group Members may or may not be registered to a
Key Server in its GDOI Group on the same network device being
queried.
oacGdoiGmEntry entry .1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1
An entry containing Local GDOI Group Member information,
uniquely identified by Group & GM IDs. Because the Group
Member is Local to the network device being queried, TEKs
installed for this Group Member can be queried …
Indexes
oacGdoiGroupName oacGdoiGmActiveKEK
Column Syntax OID
oacGdoiGmIdType
The Identification Type Value used to parse the identity
information for a Initiator or Group Member. RFC 4306
defines all valid types that can be used as an identifier.
These identification types are sent as the 'SRC …
OacGdoiIdentificationType
Textual Convention: OacGdoiIdentificationType Enumeration
Type Values:
1keyID
2ipv4
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1.1
oacGdoiGmIdValue
The value of the identity information for a Group Member with
its type indicated by the oacGdoiGmIdType. Use the
oacGdoiGmIdType to parse the Group Member ID correctly.
This Group Member ID value is sent as the 'SRC
Id…
OacGdoiIdentificationValue
Textual Convention: OacGdoiIdentificationValue OctetString
Type Constraints:
range: 0..16
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1.2
oacGdoiGmRegKeyServerIdValue
The value of the identity information for this Group Member's
registered Key Server with its type indicated by the
oacGdoiGmRegKeyServerIdType. Use the
oacGdoiGmRegKeyServerIdType to parse the registered Key
Server's I…
OacGdoiIdentificationValue
Textual Convention: OacGdoiIdentificationValue OctetString
Type Constraints:
range: 0..16
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1.3
oacGdoiGmActiveKEK
The SPI of the Key Encryption Key (KEK) that is currently
being used by the Group Member to authenticate & decrypt a
rekey from a GROUPKEY-PUSH message.
OacGdoiSPI
Textual Convention: OacGdoiSPI OctetString
Type Constraints:
range: 32
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1.4
oacGdoiGmRekeysReceived
The sequence number of the last rekey successfully received
from this Group Member's registered Key Server.
GROUPKEY-PUSH MessagesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1.5
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2 · 1 row entry · 10 columns
A table of information regarding GDOI Key Encryption Key
(KEK) Security Associations (SAs) currently installed for
GDOI entities acting as Group Members on the network device
being queried.  There is one entry in this table for each
KEK SA that has been installed and not yet deleted.  Each
KEK SA is uniquely identified by a SPI at any given time.
oacGdoiGmKekEntry entry .1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1
An entry containing the attributes associated with a GDOI KEK
SA, uniquely identified by the Group ID, Group Member (GM)
ID, & SPI value assigned by the GM's registered Key Server to
the KEK. There will be at least one…
Indexes
oacGdoiGroupName oacGdoiGmKekSPI
Column Syntax OID
oacGdoiGmKekSPI
The value of the Security Parameter Index (SPI) of a KEK
SA. The SPI must be the ISAKMP Header cookie pair
where the first 8 octets become the 'Initiator Cookie' field
of the GROUPKEY-PUSH message ISAKMP HDR, and the s…
OacGdoiSPI
Textual Convention: OacGdoiSPI OctetString
Type Constraints:
range: 32
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.1
oacGdoiGmKekSrcIdValue
The value of the identity information for the source of
a KEK SA with its type indicated by the
oacGdoiGmKekSrcIdType. Use the oacGdoiGmKekSrcIdType to parse
the KEK Source ID correctly. This ID value is sent as the …
OacGdoiIdentificationValue
Textual Convention: OacGdoiIdentificationValue OctetString
Type Constraints:
range: 0..16
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.2
oacGdoiGmKekDstIdValue
The value of the identity information for the destination of
a KEK SA (multicast rekey address) with its type indicated by
oacGdoiGmKekDstIdType. Use the oacGdoiGmKekDstIdType to parse
the KEK Dest. ID correctly. Th…
OacGdoiIdentificationValue
Textual Convention: OacGdoiIdentificationValue OctetString
Type Constraints:
range: 0..16
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.3
oacGdoiGmKekEncryptAlg
The value of the KEK_ALGORITHM which specifies the
encryption algorithm used with the KEK SA. A GDOI
implementaiton must support KEK_ALG_3DES.

Following are the KEK encryption algoritm values defined in
OacGdoiKEKEncryptionAlgorithm
Textual Convention: OacGdoiKEKEncryptionAlgorithm Enumeration
Type Values:
1enc-des
2enc-3des
3enc-aes
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.4
oacGdoiGmKekEncryptKeyLength
The value of the KEK_KEY_LENGTH which specifies the KEK
Algorithm key length (in bits).
BitsSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.5
oacGdoiGmKekSigHashAlg
The value of the SIG_HASH_ALGORITHM which specifies the SIG
payload hash algorithm. This is not required (i.e. could
have a value of zero) if the SIG_ALGORITHM is SIG_ALG_DSS or
SIG_ALG_ECDSS, which imply SIG_HASH_SHA1…
OacGdoiHashAlogrithm
Textual Convention: OacGdoiHashAlogrithm Enumeration
Type Values:
1md5
2sha1
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.6
oacGdoiGmKekSigAlg
The value of the SIG_ALGORITHM which specifies the SIG
payload signature algorithm. A GDOI implementation must
support SIG_ALG_RSA
OacGdoiSignatureMethod
Textual Convention: OacGdoiSignatureMethod Enumeration
Type Values:
1rsa
2dss
3ecdss
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.7
oacGdoiGmKekSigKeyLength
The value of the SIG_KEY_LENGTH which specifies the length
of the SIG payload key.
BitsSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.8
oacGdoiGmKekOriginalLifetime
The value of the KEK_KEY_LIFETIME which specifies the maximum
time for which a KEK is valid. The GCKS may refresh the KEK
at any time before the end of the valid period. The value is
a four (4) octet (32-bit) number d…
SecondsSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.9
oacGdoiGmKekRemainingLifetime
The value of the remaining time for which a KEK is valid.
The value is a four (4) octet (32-bit) number which begins at
the value of oacGdoiGmKekOriginalLifetime and counts down to 0
in seconds. If the lifetime has alr…
SecondsSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.10