ciscoEnhIpsecFlowCertExpiry
CISCO-ENHANCED-IPSEC-FLOW-MIB ·
.1.3.6.1.4.1.9.9.432.0.6
Object
notification
This notification is generated to notify that an X.509 certificate is going to expire. The notification is triggered the time threshold configured on the application for notification before the certificate is going to expire, which is when the value of ceipSecCertExpiryStatus is changed from certOK(1) to certGoingExpired(2). The user should take action to renew the certificate identified in the notification prior to the certificate expiration, which is at the validity notAfter time provided in the notification.
Context
- MIB
- CISCO-ENHANCED-IPSEC-FLOW-MIB
- OID
.1.3.6.1.4.1.9.9.432.0.6- Type
- notification
- Status
- current
- Parent
- ciscoEnhancedIpsecFlowMIBNotifs
- Siblings
- 6
Syntax
No syntax metadata recorded.
Values & Constraints
No enumerated values or constraints recorded.
Related Objects
Sibling Objects
| Object | Type | Syntax | OID |
|---|---|---|---|
| ciscoEnhIpsecFlowTunnelStart This notification is generated when an IPsec Phase-2
Tunnel becomes active. | notification | - | .1.3.6.1.4.1.9.9.432.0.1 |
| ciscoEnhIpsecFlowTunnelStop This notification is generated when an IPsec Phase-2
Tunnel becomes inactive. | notification | - | .1.3.6.1.4.1.9.9.432.0.2 |
| ciscoEnhIpsecFlowSysFailure This notification is generated when the processing
for an IPsec Phase-2 Tunnel experiences an internal
or system capacity error. | notification | - | .1.3.6.1.4.1.9.9.432.0.3 |
| ciscoEnhIpsecFlowSetupFail This notification is generated when the setup for
an IPsec Phase-2 Tunnel fails. | notification | - | .1.3.6.1.4.1.9.9.432.0.4 |
| ciscoEnhIpsecFlowBadSa This notification is generated when the managed
entity receives an IPsec packet with a non-existent
(non-existant in the local Security Association
Database) SPI. | notification | - | .1.3.6.1.4.1.9.9.432.0.5 |
| ciscoEnhIpsecFlowCertRenewal This notification is generated to report a status transition
for an X.509 certificate renewal performed by the application.
The notification is generated when the value of
ceipSec… | notification | - | .1.3.6.1.4.1.9.9.432.0.7 |
Notification Objects
| Object | Type | Syntax | OID |
|---|---|---|---|
| ceipSecCertSubjectName This object provides the subject name from the X.509
certificate, or the alternate subject name if it is available.
The subject name is formatted as a character string matching th… | scalar | SNMP-FRAMEWORK-MIBSnmpAdminString | .1.3.6.1.4.1.9.9.432.1.6.1 |
| ceipSecCertSerialNumber This object provides the serial number from the X.509
certificate. The serial number is formatted as a character
string matching the output of a ssh-certview command-line
applicat… | scalar | SNMP-FRAMEWORK-MIBSnmpAdminString | .1.3.6.1.4.1.9.9.432.1.6.2 |
| ceipSecCertIssuerName This object provides the issuer name from the X.509
certificate. The issuer name is formatted as a character string
matching the output of a ssh-certview command-line application,… | scalar | SNMP-FRAMEWORK-MIBSnmpAdminString | .1.3.6.1.4.1.9.9.432.1.6.3 |
| ceipSecCertExpiryTime This object provides the validity notAfter time from the X.509
certificate. The notAfter time is the time after which the
certificate is not valid. The time is formatted as a char… | scalar | SNMP-FRAMEWORK-MIBSnmpAdminString | .1.3.6.1.4.1.9.9.432.1.6.4 |
| ceipSecCertExpiryStatus This object provides the expiration status of the X.509
certificate on the application sending the notification.
The notification is sent when the value of this object is
changed … | scalar | Enumeration | .1.3.6.1.4.1.9.9.432.1.6.6 |