Home/Catalog/CISCO-PKI-MIB

CISCO-PKI-MIB

AI MIB Summary

The CISCO-PKI-MIB monitors and manages the state of Cisco Public Key Infrastructure components, including certificate authority servers, enrollment agents, and certificate revocation lists, by exposing metrics for certificate validity, issuance status, and revocation events. This module facilitates the automated tracking of cryptographic key lifecycles and trust anchor health across Cisco IOS, IOS-XE, and NX-OS platforms to ensure secure authentication and encryption operations.

description
Main OID:
ciscoPkiMIB.1.3.6.1.4.1.9.9.854
70
Objects
Active
Status
4
Dependencies

Imported Objects

Objects

70 total
Object Name
ciscoPkiMIBdescription
MODULE-IDENTITY
.1.3.6.1.4.1.9.9.854
ciscoPkiMIBNotifs
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.1
ciscoPkiCertInstallAlertWhen a certificate is installed on the device, notification will be sent with following information. a) Certificates Serial number b) Certificate Issuer-name c) Certificate Subject name d) Trustpoint name e) Type of certificate. (i.e. CA/ID) certificate f) Certificate Start Date g) Certificate End Date Alert will not be sent for RA certificates, trustpool certificates and self-signed non-persistent certificates.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.854.1.1
ciscoPkiCertExpiryAlertCertificate Expiry alert consists of following a) Certificate Serial number b) Certificate Issuer-name c) Trustpoint name d) Type of certificate (i.e. CA/ID/SUBCA/RA) e) Certificate remaining lifetime in seconds. f) Certificate subject-name When a certificate is reaching its expiry on the router, a trap will be sent to SNMP server at regular intervals starting from 60days to till 1week. From 1week onwards daily one trap will be sent with following information a) Certificate Serial number b) Certificate Issuer-name c) Trustpoint name d) Type of certificate (i.e. CA/ID) e) Certificate remaining lifetime. Alert will not be sent if trustpoint is configured with auto-enroll and corresponding shadow certificate/rollover certificate is present provided, shadow/rollover certificates start time is same/behind certificate end time. If shadow/rollover certificate start time is ahead of certificate end time, alerts will be continued to send because shadow certificate wont be valid from certificates expiry time. Expiry alerts will not be sent for trustpool certificates.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.854.1.2
ciscoPkiMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.2
ciscoPkiConfiguration
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.2.1
ciscoPkiEnrollmentProfile
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.2.1.1
ciscoPkiEnrollmentTablePlease enter the Table Description here.
SEQUENCE OF EnrollProfEntry
.1.3.6.1.4.1.9.9.854.2.1.1.1
enrollProfEntryAn entry (conceptual row) in the xxxTable.
EnrollProfEntry
.1.3.6.1.4.1.9.9.854.2.1.1.1.1
enrollProfLabelUnique value to display Enrollment Label. If enrollment profiles are not present, string size of 0 will show nothing.
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.3
enrolCredentialsPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.4
authLocationPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.5
authMethodPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.6
authVrfPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.7
authSourceInterPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.8
enrolMethodEnrollment method will be displayed which will be used to authenticate and enroll. If enrollment method is configured as terminal, this parameter gives enrollment terminal If enrollment method is configured with url, this parameter returns enrollment url ip_addresss If vrf is configured as part of enrollment url, it will be shown as part of enrollment url ip_address vrf interfacero
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.9
enrolLocationPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.10
enrolVrfPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.11
enrolSourceInterPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.12
reenrolMethodPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.13
reenrolLocationPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.14
reenrolVrfPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.15
reenrolSourceInterPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.1.1.1.16
ciscoPkiTrustpoints
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.2.1.2
pkiTPTablePlease enter the Table Description here.
SEQUENCE OF PkiTPEntry
.1.3.6.1.4.1.9.9.854.2.1.2.1
pkiTPEntryAn entry (conceptual row) in the xxxTable.
PkiTPEntry
.1.3.6.1.4.1.9.9.854.2.1.2.1.1
tpLabelUnique name of Trustpoint Label. When there is no trustpoint configured, size 0 shows no trustpoint configured.
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.1
subjectNameSubject name configured under the trustpoint will be returnedro
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.2
subjectAltNamesubject alternate name configured under the trustpoint which can be used while generating the csr.ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.3
aaaListInfoReturns AAA authorization list to be used configured under trustpoint. AAA authorization list will be used during peer certificate validations etc. In order to access information on AAA list, please check AAA MIB corresponding to this AAA label.ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.4
enrollmentConfigEnrollment configuration which is configured under the trustpoint will be returned.ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.5
vrfConfigVRF interface configured under trustpoint which can be used for enrollment and obtaining CRL'sro
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.6
sourceIntersource Interface configured under trustpoint.ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.7
autoEnrollIf autoEnroll is configured under the trustpoint, autoEnroll returns with the percentage configured. If the percentage is not configured, but auto-enroll is configured under trustpoint, this parameter return auto-enroll. If percentage is configured, parameter returns auto-enroll <percentage>ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.8
keyPairLabelDisplays keypairLabel associated to this trustpoint if it is enrolled. During authentication, we wont generate the keypair Label.ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.10
revocationMethodThis object displays revocation check configured on the device. If nothing is configured under the trustpoint, by default revocation-check crl will be updated.ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.11
hashAlgoHash algorithm configured under the trustpoint. This will be used while selecting the HASH algorithm when CA server responded with GetCACapabilities list. Default value is sha1ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.12
trustpointStateTrustpoint state displays following 1) Authenticated - Trustpoint is in Authenticated state. 2) Enrolled - Trustpoint is authenticated and enrolled. Certificate state is granted. 3) Pending - Trustpoint is authenticated but enrollment is in pending state. This means CA server returned PENDING for the router certificate. 4) None - Trustpoint is neither authenticated nor enrolled.ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.1.2.1.1.13
ciscoPkiCertificates
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.2.2
certChainTablePlease enter the Table Description here.
SEQUENCE OF CertChainEntry
.1.3.6.1.4.1.9.9.854.2.2.1
certChainEntryAn entry (conceptual row) in the xxxTable.
CertChainEntry
.1.3.6.1.4.1.9.9.854.2.2.1.1
certChainLabelPlease enter the object description here
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.2.1.1.1
certSerialNumPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.2.1.1.2
certIssuerNamePlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.2.1.1.3
certStartDatePlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.2.1.1.4
certEndDatePlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.2.1.1.5
certTypePlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.2.1.1.6
certRemainingLifePlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.2.1.1.7
certTpLabelPlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.2.1.1.8
certSubNamePlease enter the object description herero
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.2.1.1.9
ciscoPkiRevocationInfo
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.2.3
ciscoPkiCRLInfo
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.2.3.1
pkiCRLTablePlease enter the Table Description here.
SEQUENCE OF PkiCRLEntry
.1.3.6.1.4.1.9.9.854.2.3.1.1
pkiCRLEntryAn entry (conceptual row) in the xxxTable.
PkiCRLEntry
.1.3.6.1.4.1.9.9.854.2.3.1.1.1
crlTpLabelUnique trustpoint Label
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.1
issuerNameCRL Issuer namero
DisplayString
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.2
sequenceNumbPlease enter the object description herero
DisplayString
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.3
nextUpdatePlease enter the object description herero
DisplayString
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.4
crlSizePlease enter the object description herero
Unsigned32
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.5
deltaCRLFlagThis object specifies the storage type for this conceptual row. The following columnar objects are allowed to be writable when the storageType of this conceptual row is permanent(4): (replace with list of columns)ro
Unsigned32
.1.3.6.1.4.1.9.9.854.2.3.1.1.1.6
ciscoPkiOSCPInfo
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.2.3.2
pkiOCSPTablePlease enter the Table Description here.
SEQUENCE OF PkiOCSPEntry
.1.3.6.1.4.1.9.9.854.2.3.2.1
pkiOCSPEntryAn entry (conceptual row) in the xxxTable.
PkiOCSPEntry
.1.3.6.1.4.1.9.9.854.2.3.2.1.1
ocspTpLabelPlease enter the object description here
DisplayString
.1.3.6.1.4.1.9.9.854.2.3.2.1.1.1
responderIDAn identifier of the responder (DN name or a hash of its key)ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.3.2.1.1.2
thisUpdateThe issuing time of the revocation information.ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.3.2.1.1.3
nexUpdateThe issuing time of the revocation information that will update that one.ro
DisplayString
.1.3.6.1.4.1.9.9.854.2.3.2.1.1.4
ciscoPkiMIBConform
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.3
ciscoPkiMIBCompliances
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.3.1
ciscoPkiMIBGroups
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.854.3.2
CISCO-PKI-MIB - SNMP MIB Reference | MIBs Explorer