CISCOSB-SECSD-MIB
AI MIB Summary
The CISCOSB-SECSD-MIB module enables Cisco devices to monitor and manage access controls for Security Sensitive Data (SSD), specifically tracking user credentials and authentication states across CLI, web, and other management channels. This private MIB provides visibility into the exposure and protection mechanisms for sensitive system information such as usernames and passwords.
The private MIB module definition for Security Sensitive Data (SSD), contains the MIB tables and scalars to manage the access through the different management channels as CLI, WEB and others, for sensitive data as user names and passwords in system.
Main OID:
rlSecSd.1.3.6.1.4.1.9.6.1.101.209
25
Objects
Active
Status
4
Dependencies
Imported Objects
Objects
25 total| Object Name |
|---|
rlSecSdThe private MIB module definition for Security Sensitive Data (SSD), contains the MIB tables and scalars to manage the access through the different management channels as CLI, WEB and others, for sensitive data as user names and passwords in system. MODULE-IDENTITY .1.3.6.1.4.1.9.6.1.101.209 |
rlSecSdRulesTableThe table holding the Security Sensitive Data access rules per: user name / user level and management channel. Allow to add/edit/remove Security Sensitive Data rules. SEQUENCE OF RlSecSdRulesEntry .1.3.6.1.4.1.9.6.1.101.209.1 |
rlSecSdRulesEntryAn entry in the rlSecSdRulesTable. RlSecSdRulesEntry .1.3.6.1.4.1.9.6.1.101.209.1.1 |
rlSecSdRuleUserContains the Rule user type as described in RlSecSdRuleUserType.rw RlSecSdRuleUserType .1.3.6.1.4.1.9.6.1.101.209.1.1.1 |
rlSecSdRuleUserNameContains the Rule user name when rlSecSdRuleUser value is user-name, Otherwise it contains an empty stringrw DisplayString .1.3.6.1.4.1.9.6.1.101.209.1.1.2 |
rlSecSdRuleChannelContains the Rule management channel type as described in RlSecSdChannelType. secure-xml-snmp and insecure-xml-snmp management channels have no include-encrypted capability thus their rlSecSdRulePermitRead and rlSecSdRuleRead can have only RlSecSdAccessType values of exclude or include-decrypted.rw RlSecSdChannelType .1.3.6.1.4.1.9.6.1.101.209.1.1.3 |
rlSecSdRuleReadContains the Rule default read access level as described in RlSecSdAccessType, must be lower or equal access from rlSecSdRulePermitReadrw RlSecSdAccessType .1.3.6.1.4.1.9.6.1.101.209.1.1.4 |
rlSecSdRulePermitReadContains the Rule maximum permission access level as described in RlSecSdPermitAccessType.rw RlSecSdPermitAccessType .1.3.6.1.4.1.9.6.1.101.209.1.1.5 |
rlSecSdRuleIsDefaulttrue - Rule has created by the by the system. false - Rule has created by the user.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.6.1.101.209.1.1.6 |
rlSecSdRuleOwnerContains the current Rule ownership as defined in RlSecSdRuleOwnerType. when rlSecSdRuleIsDefault is true, rlSecSdRuleOwner allowed to change default rule to user rule and vice versa.rw RlSecSdRuleOwnerType .1.3.6.1.4.1.9.6.1.101.209.1.1.7 |
rlSecSdRuleStatusThe status of a table entry. It is used to Add/Edit/Delete an entry from this table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.6.1.101.209.1.1.8 |
rlSecSdMngSessionsTableThe table holding Security Sensitive Data management sessions. Allowing to get management channel, user name, user level. SEQUENCE OF RlSecSdMngSessionsEntry .1.3.6.1.4.1.9.6.1.101.209.2 |
rlSecSdMngSessionsEntryAn entry in the rlSecSdMngSessionsTable. RlSecSdMngSessionsEntry .1.3.6.1.4.1.9.6.1.101.209.2.2 |
rlSecSdMngSessionIdContains the Security Sensitive Data management session identifier, rlSecSdCurrentSessionId is used to get the current management session identifierro INTEGER .1.3.6.1.4.1.9.6.1.101.209.2.2.1 |
rlSecSdMngSessionUserLevelContains the Security Sensitive Data management session user access level.ro INTEGER .1.3.6.1.4.1.9.6.1.101.209.2.2.2 |
rlSecSdMngSessionUserNameContains the Security Sensitive Data management session user name.rw DisplayString .1.3.6.1.4.1.9.6.1.101.209.2.2.3 |
rlSecSdMngSessionChannelContains the Security Sensitive Data management session channel type as described in RlSecSdChannelType.ro RlSecSdChannelType .1.3.6.1.4.1.9.6.1.101.209.2.2.4 |
rlSecSdSessionControlAction scalar which set the default read access of Security Sensitive Data. Affect only on session which from this scalar is configured. Scalar Get value is the default-display/read of the session which from this scalar is retrieved.rw RlSecSdSessionAccessType .1.3.6.1.4.1.9.6.1.101.209.3 |
rlSecSdCurrentSessionIdGet the current SSD management channel identifier, used to get information from rlSecSdMngSessionsTable.ro INTEGER .1.3.6.1.4.1.9.6.1.101.209.4 |
rlSecSdPassPhraseSet the passphrase for the SSD encryptyption / decryption key. on set, passphrase is in plain text format. on get, passphrase is encrypted.rw DisplayString .1.3.6.1.4.1.9.6.1.101.209.5 |
rlSecSdFilePassphraseControlFile Passphrase control provides an additional level of protection on passphrase and configurations. restricted - a device restricts its passphrase from being inserted into a configuration file. unrestricted - (default) a device will include its passphrase when creating a configuration file.rw Enumeration .1.3.6.1.4.1.9.6.1.101.209.6 |
rlSecSdFileIntegrityControlFile integrity control provides a validation of configuration file. enable - Validate the configuration file digest when downloading the file to startup configuration. disable - Do not validate.rw Enumeration .1.3.6.1.4.1.9.6.1.101.209.7 |
rlSecSdConfigurationFileSsdDigestSSD block in configuration file integrity digest, auxiliary action scalar for internal system using during configuration download.rw DisplayString .1.3.6.1.4.1.9.6.1.101.209.8 |
rlSecSdConfigurationFileDigestSSD configuration file integrity digest, auxiliary action scalar for internal system using during configuration download.rw DisplayString .1.3.6.1.4.1.9.6.1.101.209.9 |
rlSecSdFileIndicatorRetrieve configuration file SSD indicator. set value: configuration file name. get value: Exclude, Encrypted, Plaintextrw DisplayString .1.3.6.1.4.1.9.6.1.101.209.10 |