MIB Viewer

CISCO-GDOI-MIB

221 objects
This MIB module defines objects for managing the GDOI protocol. Copyright (c) The IETF Trust (2010). This version of this MIB module is based on RFC 6407; see the RFC itself for full legal notices.
Imported Objects
CISCO-SMIciscoMgmt
CISCO-TCCiscoMilliSeconds
SNMPv2-CONFMODULE-COMPLIANCE NOTIFICATION-GROUP OBJECT-GROUP
SNMPv2-SMICounter32 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE Unsigned32
SNMPv2-TCDisplayString TEXTUAL-CONVENTION TruthValue
OIDNameAccessStatusDescription
1.3.6.1.4.1.9.9.759IdentityciscoGdoiMIBThis MIB module defines objects for managing the GDOI protocol. Copyright (c) The IETF Trust (2010). This version of this MIB module is based on RFC 6407; see …
1.3.6.1.4.1.9.9.759.0NodecgmGdoiMIBNotifications
1.3.6.1.4.1.9.9.759.0.1NotificationcgmGdoiKeyServerNewRegistrationcurrentA notification from a Key Server sent when a new Group Member registers to a GDOI Group. This is equivalent to a Key Server receiving the first message of a GR…
1.3.6.1.4.1.9.9.759.0.2NotificationcgmGdoiKeyServerRegistrationCompletecurrentA notification from a Key Server sent when a Group Member has successfully registered to itself. This is equivalent to a Key Server sending the last message of…
1.3.6.1.4.1.9.9.759.0.3NotificationcgmGdoiKeyServerRekeyPushedcurrentA notification from a Key Server sent when a GROUPKEY-PUSH message is sent to refresh KEK(s) and or TEK(s). A rekey is sent periodically by a Key Server based …
1.3.6.1.4.1.9.9.759.0.4NotificationcgmGdoiKeyServerNoRsaKeyscurrentAn error notification from a Key Server sent when an RSA key is not setup. Each Key Server and Group Member needs to have an RSA key established. The Key Serve…
1.3.6.1.4.1.9.9.759.0.5NotificationcgmGdoiGmRegistercurrentA notification from a Group Member when it is starting to register with its GDOI Group's Key Server. Registration includes downloading keying & security associ…
1.3.6.1.4.1.9.9.759.0.6NotificationcgmGdoiGmRegistrationCompletecurrentA notification from a Group Member when it has successfully registered with a Key Server in its GDOI Group. This is equivalent to a Group Member receiving the …
1.3.6.1.4.1.9.9.759.0.7NotificationcgmGdoiGmReRegistercurrentA notification from a Group Member when it is starting to re-register with a Key Server in its GDOI Group. A Group Member needs to re-register to the key serve…
1.3.6.1.4.1.9.9.759.0.8NotificationcgmGdoiGmRekeyReceivedcurrentA notification from a Group Member when it has successfully received and processed a rekey from a Key Server in its GDOI Group. Periodically the key server sen…
1.3.6.1.4.1.9.9.759.0.9NotificationcgmGdoiGmIncompleteCfgcurrentAn error notification from a Group Member when there is necessary information missing from the policy/configuration of a Group Member on an interface when it t…
1.3.6.1.4.1.9.9.759.0.10NotificationcgmGdoiGmNoIpSecFlowscurrentAn error notification from a Group Member when no more security associations can be installed after receiving its keying & security association material. When …
1.3.6.1.4.1.9.9.759.0.11NotificationcgmGdoiGmRekeyFailurecurrentAn error notification from a Group Member when it is unable to successfully process and install a rekey (GROUPKEY-PUSH message) sent by the Key Server in its G…
1.3.6.1.4.1.9.9.759.0.12NotificationcgmGdoiKeyServerRoleChangecurrentThis notification is generated when a Key Server changes it's role from Primary to Secondary or vice-versa. The varbinds encapsulate the Group information, the…
1.3.6.1.4.1.9.9.759.0.13NotificationcgmGdoiKeyServerGmDeletedcurrentThis notification is generated when a Group Member is deleted from a Key Server. The varbinds encapsulate the Group information, the Key Server identifier and …
1.3.6.1.4.1.9.9.759.0.14NotificationcgmGdoiKeyServerPeerReachablecurrentThis notification is generated from a Key Server when an unreachable peer Key Server becomes reachable. The varbinds encapsulate the Group information, the Key…
1.3.6.1.4.1.9.9.759.0.15NotificationcgmGdoiKeyServerPeerUnreachablecurrentThis notification is generated from a Key Server when a reachable peer Key Server becomes unreachable. The varbinds encapsulate the Group information, the Key …
1.3.6.1.4.1.9.9.759.1NodecgmGdoiMIBObjects
1.3.6.1.4.1.9.9.759.1.1TablecgmGdoiGroupTablenot-accessiblecurrentA table of information regarding GDOI Groups in use on the network device being queried.
1.3.6.1.4.1.9.9.759.1.1.1RowcgmGdoiGroupEntrynot-accessiblecurrentAn entry containing GDOI Group information, uniquely identified by the GDOI Group ID.
1.3.6.1.4.1.9.9.759.1.1.1.1ColumncgmGdoiGroupIdTypenot-accessiblecurrentThe Identification Type Value used to parse a GDOI Group ID. The GDOI RFC 3547 defines the types that can be used as a GDOI Group ID, and RFC 4306 defines all …
1.3.6.1.4.1.9.9.759.1.1.1.2ColumncgmGdoiGroupIdLengthread-onlycurrentThe length (i.e. number of octets) of a Group ID. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiGroupIdType should be used…
1.3.6.1.4.1.9.9.759.1.1.1.3ColumncgmGdoiGroupIdValuenot-accessiblecurrentThe value of a Group ID with its type indicated by the cgmGdoiGroupIdType. Use the cgmGdoiGroupIdType to parse the Group ID correctly. This Group ID value is s…
1.3.6.1.4.1.9.9.759.1.1.1.4ColumncgmGdoiGroupNameread-onlycurrentThe string-readable name configured for or given to a GDOI Group.
1.3.6.1.4.1.9.9.759.1.1.1.5ColumncgmGdoiGroupMemberCountread-onlycurrentThe count of registered Group Members to this group, on a Key Server.
1.3.6.1.4.1.9.9.759.1.1.1.6ColumncgmGdoiGroupActivePeerKeyServerCountread-onlycurrentThe count of the active Key Server sessions between the local Key Server and peer Key Servers for this group.
1.3.6.1.4.1.9.9.759.1.1.1.7ColumncgmGdoiGroupLastRekeyRetransmitsread-onlycurrentThis variable returns the cummulative count of number of rekey messages and retransmits during the last cycle of rekey. This count displays the information per…
1.3.6.1.4.1.9.9.759.1.1.1.8ColumncgmGdoiGroupLastRekeyTimeTakenread-onlycurrentThis variable returns the duration (in milliseconds) of the last rekey operation. This information is valid for a Primary Key Server, and is not available with…
1.3.6.1.4.1.9.9.759.1.2NodecgmGdoiPeers
1.3.6.1.4.1.9.9.759.1.2.1TablecgmGdoiKeyServerTablenot-accessiblecurrentA table of information for the GDOI group from the perspective of the Key Servers (GCKSs) on the network device being queried.
1.3.6.1.4.1.9.9.759.1.2.1.1RowcgmGdoiKeyServerEntrynot-accessiblecurrentAn entry containing GDOI Key Server (KS) information, uniquely identified by the Group & Key Server IDs.
1.3.6.1.4.1.9.9.759.1.2.1.1.1ColumncgmGdoiKeyServerIdTypenot-accessiblecurrentThe Identification Type Value used to parse the identity information for a Key Server. RFC 4306 defines all valid types that can be used as an identifier. Thes…
1.3.6.1.4.1.9.9.759.1.2.1.1.2ColumncgmGdoiKeyServerIdLengthread-onlycurrentThe length (i.e. number of octets) of a Key Server ID. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiKeyServerIdType shoul…
1.3.6.1.4.1.9.9.759.1.2.1.1.3ColumncgmGdoiKeyServerIdValuenot-accessiblecurrentThe value of the identity information for a Key Server with its type indicated by the cgmGdoiKeyServerIdType. Use the cgmGdoiKeyServerIdType to parse the Key S…
1.3.6.1.4.1.9.9.759.1.2.1.1.4ColumncgmGdoiKeyServerActiveKEKread-onlycurrentThe SPI of the Key Encryption Key (KEK) that is currently being used by the Key Server to encrypt the GROUPKEY-PUSH keying & security association material sent…
1.3.6.1.4.1.9.9.759.1.2.1.1.5ColumncgmGdoiKeyServerRekeysPushedread-onlycurrentThe sequence number of the last rekey sent from the Key Server to its registered Group Members for this GDOI group.
1.3.6.1.4.1.9.9.759.1.2.1.1.6ColumncgmGdoiKeyServerRoleread-onlycurrentThe current role of the queried Key Server for the Group.
1.3.6.1.4.1.9.9.759.1.2.1.1.7ColumncgmGdoiKeyServerRegisteredGMsread-onlycurrentThe count of registered Group Members to the Key Server identified by the index.
1.3.6.1.4.1.9.9.759.1.2.2TablecgmGdoiGmTablenot-accessiblecurrentA table of information regarding GDOI Group Members (GMs) locally configured on the network device being queried. Note that Local Group Members may or may not …
1.3.6.1.4.1.9.9.759.1.2.2.1RowcgmGdoiGmEntrynot-accessiblecurrentAn entry containing Local GDOI Group Member information, uniquely identified by Group & GM IDs. Because the Group Member is Local to the network device being q…
1.3.6.1.4.1.9.9.759.1.2.2.1.1ColumncgmGdoiGmIdTypenot-accessiblecurrentThe Identification Type Value used to parse the identity information for a Initiator or Group Member. RFC 4306 defines all valid types that can be used as an i…
1.3.6.1.4.1.9.9.759.1.2.2.1.2ColumncgmGdoiGmIdLengthread-onlycurrentThe length (i.e. number of octets) of a Group Member ID. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiGmIdType should be …
1.3.6.1.4.1.9.9.759.1.2.2.1.3ColumncgmGdoiGmIdValuenot-accessiblecurrentThe value of the identity information for a Group Member with its type indicated by the cgmGdoiGmIdType. Use the cgmGdoiGmIdType to parse the Group Member ID c…
1.3.6.1.4.1.9.9.759.1.2.2.1.4ColumncgmGdoiGmRegKeyServerIdTyperead-onlycurrentThe Identification Type Value used to parse the identity information of this Group Member's registered Key Server. RFC 4306 defines all valid types that can be…
1.3.6.1.4.1.9.9.759.1.2.2.1.5ColumncgmGdoiGmRegKeyServerIdLengthread-onlycurrentThe length (i.e. number of octets) of the registered Key Server's ID. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiGmRegK…
1.3.6.1.4.1.9.9.759.1.2.2.1.6ColumncgmGdoiGmRegKeyServerIdValueread-onlycurrentThe value of the identity information for this Group Member's registered Key Server with its type indicated by the cgmGdoiGmRegKeyServerIdType. Use the cgmGdoi…
1.3.6.1.4.1.9.9.759.1.2.2.1.7ColumncgmGdoiGmActiveKEKread-onlycurrentThe SPI of the Key Encryption Key (KEK) that is currently being used by the Group Member to authenticate & decrypt a rekey from a GROUPKEY-PUSH message.
1.3.6.1.4.1.9.9.759.1.2.2.1.8ColumncgmGdoiGmRekeysReceivedread-onlycurrentThe sequence number of the last rekey successfully received from this Group Member's registered Key Server.
1.3.6.1.4.1.9.9.759.1.2.2.1.9ColumncgmGdoiGmActiveTEKNumread-onlycurrentThe number of active traffic encryption keys (TEKS) currently being used by the Group Member to encrypt/decrypt/authenticate dataplane traffic.
1.3.6.1.4.1.9.9.759.1.2.3TablecgmGdoiCoopPeerTablenot-accessiblecurrentA table of information for the COOP peer(s). The information populated in this table, is extracted from the COOP messages exchanged between the local KS (devic…
1.3.6.1.4.1.9.9.759.1.2.3.1RowcgmGdoiCoopPeerEntrynot-accessiblecurrentAn entry containing COOP Peer Key Server's (KS) information, uniquely identified by the Group & Peer Key Server IDs.
1.3.6.1.4.1.9.9.759.1.2.3.1.1ColumncgmGdoiCoopPeerIdTypenot-accessiblecurrentThe Identification Type Value used to parse the identity information for a Key Server. RFC 4306 defines all valid types that can be used as an identifier. Thes…
1.3.6.1.4.1.9.9.759.1.2.3.1.2ColumncgmGdoiCoopPeerIdLengthread-onlycurrentThe length (i.e. number of octets) of a Peer (Key Server) ID. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiCoopPeerIdType…
1.3.6.1.4.1.9.9.759.1.2.3.1.3ColumncgmGdoiCoopPeerIdValuenot-accessiblecurrentThe value of the identity information for a COOP Key Server with its type indicated by the cgmGdoiCoopPeerIdType. Use the cgmGdoiCoopPeerIdType to parse the CO…
1.3.6.1.4.1.9.9.759.1.2.3.1.4ColumncgmGdoiCoopPeerRoleread-onlycurrentThe current role of the COOP Peer (Key Server) for the Group.
1.3.6.1.4.1.9.9.759.1.2.3.1.5ColumncgmGdoiCoopPeerStatusread-onlycurrentThe current status of the COOP Peer (Key Server) as seen from the local Key Server.
1.3.6.1.4.1.9.9.759.1.2.3.1.6ColumncgmGdoiCoopPeerRegisteredGMsread-onlycurrentThe count of registered Group Members to the COOP Peer (Key Server) identified by the index.
1.3.6.1.4.1.9.9.759.1.3NodecgmGdoiSecAssociations
1.3.6.1.4.1.9.9.759.1.3.1TablecgmGdoiKsKekTablenot-accessiblecurrentA table of information regarding GDOI Key Encryption Key (KEK) Policies & Security Associations (SAs) currently configured/installed for GDOI entities acting a…
1.3.6.1.4.1.9.9.759.1.3.1.1RowcgmGdoiKsKekEntrynot-accessiblecurrentAn entry containing the attributes associated with a GDOI KEK Policy/SA, uniquely identified by the Group ID, Key Server ID, & SPI value assigned by the given …
1.3.6.1.4.1.9.9.759.1.3.1.1.1ColumncgmGdoiKsKekIndexnot-accessiblecurrentThe index of the KS KEK.The value of the index is a number which begins at one and is incremented with each KS KEK that is to be created by the KS for that GDO…
1.3.6.1.4.1.9.9.759.1.3.1.1.2ColumncgmGdoiKsKekSPIread-onlycurrentThe value of the Security Parameter Index (SPI) of a KEK Policy/SA. The SPI must be the ISAKMP Header cookie pair where the first 8 octets become the 'Initiato…
1.3.6.1.4.1.9.9.759.1.3.1.1.3ColumncgmGdoiKsKekSrcIdTyperead-onlycurrentThe Identification Type Value used to parse the identity information for the source of a KEK Policy/SA. RFC 4306 defines all valid types that can be used as an…
1.3.6.1.4.1.9.9.759.1.3.1.1.4ColumncgmGdoiKsKekSrcIdLengthread-onlycurrentThe length (i.e. number of octets) of the source ID of a KEK Policy/SA. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiKsKe…
1.3.6.1.4.1.9.9.759.1.3.1.1.5ColumncgmGdoiKsKekSrcIdValueread-onlycurrentThe value of the identity information for the source of a KEK Policy/SA with its type indicated by the cgmGdoiKsKekSrcIdType. Use the cgmGdoiKsKekSrcIdType to …
1.3.6.1.4.1.9.9.759.1.3.1.1.6ColumncgmGdoiKsKekSrcIdPortread-onlycurrentThe value specifying a port associated with the source ID of a KEK Policy/SA. A value of zero means that the port should be ignored. This port value is sent as…
1.3.6.1.4.1.9.9.759.1.3.1.1.7ColumncgmGdoiKsKekDstIdTyperead-onlycurrentThe Identification Type Value used to parse the identity information for the dest. of a KEK Policy/SA (multicast rekey address). RFC 4306 defines all valid typ…
1.3.6.1.4.1.9.9.759.1.3.1.1.8ColumncgmGdoiKsKekDstIdLengthread-onlycurrentThe length (i.e. number of octets) of the destination ID of a KEK Policy/SA (multicast rekey address). If no length is given (i.e. it has a valueof 0), the def…
1.3.6.1.4.1.9.9.759.1.3.1.1.9ColumncgmGdoiKsKekDstIdValueread-onlycurrentThe value of the identity information for the destination of a KEK Policy/SA (multicast rekey address) with its type indicated by the cgmGdoiKsKekDstIdType. Us…
1.3.6.1.4.1.9.9.759.1.3.1.1.10ColumncgmGdoiKsKekDstIdPortread-onlycurrentThe value specifying a port associated with the dest. ID of a KEK Policy/SA. A value of zero means that the port should be ignored. This port value is sent as …
1.3.6.1.4.1.9.9.759.1.3.1.1.11ColumncgmGdoiKsKekIpProtocolread-onlycurrentThe value of the IP protocol ID (e.g. UDP/TCP) being used for the rekey datagram.
1.3.6.1.4.1.9.9.759.1.3.1.1.12ColumncgmGdoiKsKekMgmtAlgread-onlycurrentThe value of the KEK_MANAGEMENT_ALGORITHM which specifies the group KEK management algorithm used to provide forward or backward access control (i.e. used to e…
1.3.6.1.4.1.9.9.759.1.3.1.1.13ColumncgmGdoiKsKekEncryptAlgread-onlycurrentThe value of the KEK_ALGORITHM which specifies the encryption algorithm used with the KEK Policy/SA. A GDOI implementaiton must support KEK_ALG_3DES. Following…
1.3.6.1.4.1.9.9.759.1.3.1.1.14ColumncgmGdoiKsKekEncryptKeyLengthread-onlycurrentThe value of the KEK_KEY_LENGTH which specifies the KEK Algorithm key length (in bits).
1.3.6.1.4.1.9.9.759.1.3.1.1.15ColumncgmGdoiKsKekSigHashAlgread-onlycurrentThe value of the SIG_HASH_ALGORITHM which specifies the SIG payload hash algorithm. This is not required (i.e. could have a value of zero) if the SIG_ALGORITHM…
1.3.6.1.4.1.9.9.759.1.3.1.1.16ColumncgmGdoiKsKekSigAlgread-onlycurrentThe value of the SIG_ALGORITHM which specifies the SIG payload signature algorithm. A GDOI implementation must support SIG_ALG_RSA. Following are the Signature…
1.3.6.1.4.1.9.9.759.1.3.1.1.17ColumncgmGdoiKsKekSigKeyLengthread-onlycurrentThe value of the SIG_KEY_LENGTH which specifies the length of the SIG payload key.
1.3.6.1.4.1.9.9.759.1.3.1.1.18ColumncgmGdoiKsKekOakleyGroupread-onlycurrentThe value of the KE_OAKLEY_GROUP which specifies the OAKLEY or Diffie-Hellman Group used to compute the PFS secret in the optional KE payload of the GDOI GROUP…
1.3.6.1.4.1.9.9.759.1.3.1.1.19ColumncgmGdoiKsKekOriginalLifetimeread-onlycurrentThe value of the KEK_KEY_LIFETIME which specifies the maximum time for which a KEK is valid. The GCKS may refresh the KEK at any time before the end of the val…
1.3.6.1.4.1.9.9.759.1.3.1.1.20ColumncgmGdoiKsKekRemainingLifetimeread-onlycurrentThe value of the remaining time for which a KEK is valid. The value is a four (4) octet (32-bit) number which begins at the value of cgmGdoiKsKekOriginalLifeti…
1.3.6.1.4.1.9.9.759.1.3.1.1.21ColumncgmGdoiKsKekStatusread-onlycurrentThe status of the KEK Policy/SA. When this status value is queried, one of the following is returned: inUse(1), new(2), old(3).
1.3.6.1.4.1.9.9.759.1.3.2TablecgmGdoiGmKekTablenot-accessiblecurrentA table of information regarding GDOI Key Encryption Key (KEK) Security Associations (SAs) currently installed for GDOI entities acting as Group Members on the…
1.3.6.1.4.1.9.9.759.1.3.2.1RowcgmGdoiGmKekEntrynot-accessiblecurrentAn entry containing the attributes associated with a GDOI KEK SA, uniquely identified by the Group ID, Group Member (GM) ID, & SPI value assigned by the GM's r…
1.3.6.1.4.1.9.9.759.1.3.2.1.1ColumncgmGdoiGmKekIndexnot-accessiblecurrentThe index of the GM KEK in table.The value of the index is a number which begins at one and is incremented with each KEK that is used by the GM for that GDOI g…
1.3.6.1.4.1.9.9.759.1.3.2.1.2ColumncgmGdoiGmKekSPIread-onlycurrentThe value of the Security Parameter Index (SPI) of a KEK SA. The SPI must be the ISAKMP Header cookie pair where the first 8 octets become the 'Initiator Cooki…
1.3.6.1.4.1.9.9.759.1.3.2.1.3ColumncgmGdoiGmKekSrcIdTyperead-onlycurrentThe Identification Type Value used to parse the identity information for the source of a KEK SA. RFC 4306 defines all valid types that can be used as an identi…
1.3.6.1.4.1.9.9.759.1.3.2.1.4ColumncgmGdoiGmKekSrcIdLengthread-onlycurrentThe length (i.e. number of octets) of the source ID of a KEK SA. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiGmKekSrcIdT…
1.3.6.1.4.1.9.9.759.1.3.2.1.5ColumncgmGdoiGmKekSrcIdValueread-onlycurrentThe value of the identity information for the source of a KEK SA with its type indicated by the cgmGdoiGmKekSrcIdType. Use the cgmGdoiGmKekSrcIdType to parse t…
1.3.6.1.4.1.9.9.759.1.3.2.1.6ColumncgmGdoiGmKekSrcIdPortread-onlycurrentThe value specifying a port associated with the source ID of a KEK SA. A value of zero means that the port should be ignored. This port value is sent as the `S…
1.3.6.1.4.1.9.9.759.1.3.2.1.7ColumncgmGdoiGmKekDstIdTyperead-onlycurrentThe Identification Type Value used to parse the identity information for the dest. (multicast rekey address) of a KEK SA. RFC 4306 defines all valid types that…
1.3.6.1.4.1.9.9.759.1.3.2.1.8ColumncgmGdoiGmKekDstIdLengthread-onlycurrentThe length (i.e. number of octets) of the destination ID of a KEK SA. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiGmKekD…
1.3.6.1.4.1.9.9.759.1.3.2.1.9ColumncgmGdoiGmKekDstIdValueread-onlycurrentThe value of the identity information for the destination of a KEK SA (multicast rekey address) with its type indicated by cgmGdoiGmKekDstIdType. Use the cgmGd…
1.3.6.1.4.1.9.9.759.1.3.2.1.10ColumncgmGdoiGmKekDstIdPortread-onlycurrentThe value specifying a port associated with the dest. ID of a KEK SA. A value of zero means that the port should be ignored. This port value is sent as the `DS…
1.3.6.1.4.1.9.9.759.1.3.2.1.11ColumncgmGdoiGmKekIpProtocolread-onlycurrentThe value of the IP protocol ID (e.g. UDP/TCP) being used for the rekey datagram.
1.3.6.1.4.1.9.9.759.1.3.2.1.12ColumncgmGdoiGmKekMgmtAlgread-onlycurrentThe value of the KEK_MANAGEMENT_ALGORITHM which specifies the group KEK management algorithm used to provide forward or backward access control (i.e. used to e…
1.3.6.1.4.1.9.9.759.1.3.2.1.13ColumncgmGdoiGmKekEncryptAlgread-onlycurrentThe value of the KEK_ALGORITHM which specifies the encryption algorithm used with the KEK SA. A GDOI implementaiton must support KEK_ALG_3DES. Following are th…
1.3.6.1.4.1.9.9.759.1.3.2.1.14ColumncgmGdoiGmKekEncryptKeyLengthread-onlycurrentThe value of the KEK_KEY_LENGTH which specifies the KEK Algorithm key length (in bits).
1.3.6.1.4.1.9.9.759.1.3.2.1.15ColumncgmGdoiGmKekSigHashAlgread-onlycurrentThe value of the SIG_HASH_ALGORITHM which specifies the SIG payload hash algorithm. This is not required (i.e. could have a value of zero) if the SIG_ALGORITHM…
1.3.6.1.4.1.9.9.759.1.3.2.1.16ColumncgmGdoiGmKekSigAlgread-onlycurrentThe value of the SIG_ALGORITHM which specifies the SIG payload signature algorithm. A GDOI implementation must support SIG_ALG_RSA. Following are the Signature…
1.3.6.1.4.1.9.9.759.1.3.2.1.17ColumncgmGdoiGmKekSigKeyLengthread-onlycurrentThe value of the SIG_KEY_LENGTH which specifies the length of the SIG payload key.
1.3.6.1.4.1.9.9.759.1.3.2.1.18ColumncgmGdoiGmKekOakleyGroupread-onlycurrentThe value of the KE_OAKLEY_GROUP which specifies the OAKLEY or Diffie-Hellman Group used to compute the PFS secret in the optional KE payload of the GDOI GROUP…
1.3.6.1.4.1.9.9.759.1.3.2.1.19ColumncgmGdoiGmKekOriginalLifetimeread-onlycurrentThe value of the KEK_KEY_LIFETIME which specifies the maximum time for which a KEK is valid. The GCKS may refresh the KEK at any time before the end of the val…
1.3.6.1.4.1.9.9.759.1.3.2.1.20ColumncgmGdoiGmKekRemainingLifetimeread-onlycurrentThe value of the remaining time for which a KEK is valid. The value is a four (4) octet (32-bit) number which begins at the value of cgmGdoiGmKekOriginalLifeti…
1.3.6.1.4.1.9.9.759.1.3.2.1.21ColumncgmGdoiGmKekStatusread-onlycurrentThe status of the KEK SA. When this status value is queried, one of the following is returned: inUse(1), new(2), old(3).
1.3.6.1.4.1.9.9.759.1.3.3TablecgmGdoiKsTekSelectorTablenot-accessiblecurrentA table of information regarding GDOI Traffic Encryption Key (TEK) Selectors (source, destination, protocol information) that is currently configured/pushed fo…
1.3.6.1.4.1.9.9.759.1.3.3.1RowcgmGdoiKsTekSelectorEntrynot-accessiblecurrentAn entry containing the Source/Destination attributes associated with a GDOI TEK Policy, uniquely identified by the Group ID, Key Server ID and TEK Selector in…
1.3.6.1.4.1.9.9.759.1.3.3.1.1ColumncgmGdoiKsTekSelectorIndexnot-accessiblecurrentThe index of the Source/Destination tuple to be secured by the KS TEK.The value of the index is a number which begins at one and is incremented with each Sourc…
1.3.6.1.4.1.9.9.759.1.3.3.1.2ColumncgmGdoiKsTekSrcIdTyperead-onlycurrentThe Identification Type Value used to parse the identity information for the source of a TEK Policy. RFC 4306 defines all valid types that can be used as an id…
1.3.6.1.4.1.9.9.759.1.3.3.1.3ColumncgmGdoiKsTekSrcIdLengthread-onlycurrentThe length (i.e. number of octets) of the source ID of a TEK Policy. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiKsTekSr…
1.3.6.1.4.1.9.9.759.1.3.3.1.4ColumncgmGdoiKsTekSrcIdValueread-onlycurrentThe value of the identity information for the source of a TEK Policy with its type indicated by the cgmGdoiKsTekSrcIdType. Use the cgmGdoiKsTekSrcIdType to par…
1.3.6.1.4.1.9.9.759.1.3.3.1.5ColumncgmGdoiKsTekSrcIdPortread-onlycurrentThe value specifying a port associated with the source ID of a TEK Policy. A value of zero means that the port should be ignored. This port value is sent as th…
1.3.6.1.4.1.9.9.759.1.3.3.1.6ColumncgmGdoiKsTekDstIdTyperead-onlycurrentThe Identification Type Value used to parse the identity information for the dest. of a TEK Policy. RFC 4306 defines all valid types that can be used as an ide…
1.3.6.1.4.1.9.9.759.1.3.3.1.7ColumncgmGdoiKsTekDstIdLengthread-onlycurrentThe length (i.e. number of octets) of the destination ID of a TEK Policy. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiKs…
1.3.6.1.4.1.9.9.759.1.3.3.1.8ColumncgmGdoiKsTekDstIdValueread-onlycurrentThe value of the identity information for the destination of a TEK Policy with its type indicated by the cgmGdoiKsTekDstIdType. Use the cgmGdoiKsTekDstIdType t…
1.3.6.1.4.1.9.9.759.1.3.3.1.9ColumncgmGdoiKsTekDstIdPortread-onlycurrentThe value specifying a port associated with the dest. ID of a TEK Policy. A value of zero means that the port should be ignored. This port value is sent as the…
1.3.6.1.4.1.9.9.759.1.3.3.1.10ColumncgmGdoiKsTekSecurityProtocolread-onlycurrentThe value of the Protocol-ID field of a SA TEK (SAT) payload which specifies the Security Protocol for a TEK. Following are the Security Protocol values define…
1.3.6.1.4.1.9.9.759.1.3.4TablecgmGdoiKsTekPolicyTablenot-accessiblecurrentA table of information regarding GDOI Traffic Encryption Key (TEK) Policies currently configured/pushed for GDOI entities acting as Key Servers on the network …
1.3.6.1.4.1.9.9.759.1.3.4.1RowcgmGdoiKsTekPolicyEntrynot-accessiblecurrentAn entry containing the attributes associated with a GDOI TEK Policy, uniquely identified by the Group ID, Key Server ID, TEK Selector Index (Source/Destinatio…
1.3.6.1.4.1.9.9.759.1.3.4.1.1ColumncgmGdoiKsTekPolicyIndexnot-accessiblecurrentThe index of the policy that is used to secure the KS TEK. The value of the index is a number which begins at one and is incremented with each row in this tabl…
1.3.6.1.4.1.9.9.759.1.3.4.1.2ColumncgmGdoiKsTekSPIread-onlycurrentThe value of the Security Parameter Index (SPI) of a TEK Policy. The SPI must be the SPI for ESP.
1.3.6.1.4.1.9.9.759.1.3.4.1.3ColumncgmGdoiKsTekEncapsulationModeread-onlycurrentThe value of the Encapsulation Mode of a TEK (IPsec SA). Following are the Encapsulation Mode values defined in RFC 2407, however the CgmGdoiEncapsulationMode …
1.3.6.1.4.1.9.9.759.1.3.4.1.4ColumncgmGdoiKsTekEncryptionAlgorithmread-onlycurrentThe value of the Transform ID field of a PROTO_IPSEC_ESP payload which specifies the ESP transform to be used. If no encryption is used, this value will be zer…
1.3.6.1.4.1.9.9.759.1.3.4.1.5ColumncgmGdoiKsTekEncryptionKeyLengthread-onlycurrentThe length of the key used for encryption in a TEK (in bits).
1.3.6.1.4.1.9.9.759.1.3.4.1.6ColumncgmGdoiKsTekIntegrityAlgorithmread-onlycurrentThe value of the Authentication Algorithm for a TEK IPsec ESP SA. If no authentication is used, this value will be zero (0). Following are the Authentication A…
1.3.6.1.4.1.9.9.759.1.3.4.1.7ColumncgmGdoiKsTekIntegrityKeyLengthread-onlycurrentThe length of the key used for integrity/authentication in a TEK (in bits).
1.3.6.1.4.1.9.9.759.1.3.4.1.8ColumncgmGdoiKsTekWindowSizeread-onlycurrentThe size of the Time Based Anti-Replay (TBAR) window used by this TEK Policy.
1.3.6.1.4.1.9.9.759.1.3.4.1.9ColumncgmGdoiKsTekOriginalLifetimeread-onlycurrentThe value of the SA Life Type defined in RFC 2407 which specifies the maximum time for which a TEK IPsec SA is valid. The GCKS may refresh the TEK at any time …
1.3.6.1.4.1.9.9.759.1.3.4.1.10ColumncgmGdoiKsTekRemainingLifetimeread-onlycurrentThe value of the remaining time for which a TEK is valid. The value is a four (4) octet (32-bit) number which begins at the value of cgmGdoiKsTekOriginalLifeti…
1.3.6.1.4.1.9.9.759.1.3.4.1.11ColumncgmGdoiKsTekStatusread-onlycurrentThe status of the TEK Policy. When this status value is queried, one of the following is returned: inbound(1), outbound(2), notInUse(3).
1.3.6.1.4.1.9.9.759.1.3.5TablecgmGdoiGmTekSelectorTablenot-accessiblecurrentA table of information regarding GDOI Traffic Encryption Key (TEK) Security Associations (SAs/Policies) pushed by a Key Server & installed for GDOI entities ac…
1.3.6.1.4.1.9.9.759.1.3.5.1RowcgmGdoiGmTekSelectorEntrynot-accessiblecurrentAn entry containing the attributes associated with a GDOI TEK Policy/SA, uniquely identified by the Group ID, Group Member ID, Source/Destination IDs & Ports, …
1.3.6.1.4.1.9.9.759.1.3.5.1.1ColumncgmGdoiGmTekSelectorIndexnot-accessiblecurrentThe index of the Source/Destination pair secured by the GM TEK.The value of the index is a number which begins at one and is incremented with each Source/Desti…
1.3.6.1.4.1.9.9.759.1.3.5.1.2ColumncgmGdoiGmTekSrcIdTyperead-onlycurrentThe Identification Type Value used to parse the identity information for the source of a TEK Policy/SA. RFC 4306 defines all valid types that can be used as an…
1.3.6.1.4.1.9.9.759.1.3.5.1.3ColumncgmGdoiGmTekSrcIdLengthread-onlycurrentThe length (i.e. number of octets) of the source ID of a TEK Policy/SA. If no length is given (i.e. it has a value of 0), the default length of its cgmGdoiGmTe…
1.3.6.1.4.1.9.9.759.1.3.5.1.4ColumncgmGdoiGmTekSrcIdValueread-onlycurrentThe value of the identity information for the source of a TEK Policy/SA with its type indicated by the cgmGdoiGmTekSrcIdType. Use the cgmGdoiGmTekSrcIdType to …
1.3.6.1.4.1.9.9.759.1.3.5.1.5ColumncgmGdoiGmTekSrcIdPortread-onlycurrentThe value specifying a port associated with the source ID of a TEK Policy/SA. A value of zero means that the port should be ignored. This port value is sent as…
1.3.6.1.4.1.9.9.759.1.3.5.1.6ColumncgmGdoiGmTekDstIdTyperead-onlycurrentThe Identification Type Value used to parse the identity information for the dest. of a TEK Policy/SA. RFC 4306 defines all valid types that can be used as an …
1.3.6.1.4.1.9.9.759.1.3.5.1.7ColumncgmGdoiGmTekDstIdLengthread-onlycurrentThe length (i.e. number of octets) of the destination ID of a TEK Policy/SA. If no length is given (i.e. it has a value of 0), the default length of its cgmGdo…
1.3.6.1.4.1.9.9.759.1.3.5.1.8ColumncgmGdoiGmTekDstIdValueread-onlycurrentThe value of the identity information for the destination of a TEK Policy/SA with its type indicated by the cgmGdoiGmTekDstIdType. Use the cgmGdoiGmTekDstIdTyp…
1.3.6.1.4.1.9.9.759.1.3.5.1.9ColumncgmGdoiGmTekDstIdPortread-onlycurrentThe value specifying a port associated with the dest. ID of a TEK Policy/SA. A value of zero means that the port should be ignored. This port value is sent as …
1.3.6.1.4.1.9.9.759.1.3.5.1.10ColumncgmGdoiGmTekSecurityProtocolread-onlycurrentThe value of the Protocol-ID field of a SA TEK (SAT) payload which specifies the Security Protocol for a TEK. Following are the Security Protocol values define…
1.3.6.1.4.1.9.9.759.1.3.6TablecgmGdoiGmTekPolicyTablenot-accessiblecurrentA table of information regarding GDOI Traffic Encryption Key (TEK) Security Associations (SAs/Policies) received by a Key Server & installed for GDOI entities …
1.3.6.1.4.1.9.9.759.1.3.6.1RowcgmGdoiGmTekPolicyEntrynot-accessiblecurrentAn entry containing the attributes associated with a GDOI TEK Policy/SA, uniquely identified by the Group ID, Group Member ID, TEK Selector (Source/Destination…
1.3.6.1.4.1.9.9.759.1.3.6.1.1ColumncgmGdoiGmTekPolicyIndexnot-accessiblecurrentThe index of the SPI used to secure the GM TEK.The value of the index is a number which begins at one and is incremented with each row of the GM TEK SPI table.
1.3.6.1.4.1.9.9.759.1.3.6.1.2ColumncgmGdoiGmTekSPIread-onlycurrentThe value of the Security Parameter Index (SPI) of a TEK Policy/SA. The SPI must be the SPI for ESP.
1.3.6.1.4.1.9.9.759.1.3.6.1.3ColumncgmGdoiGmTekEncapsulationModeread-onlycurrentThe value of the Encapsulation Mode of a TEK (IPsec SA). Following are the Encapsulation Mode values defined in RFC 2407, however the CgmGdoiEncapsulationMode …
1.3.6.1.4.1.9.9.759.1.3.6.1.4ColumncgmGdoiGmTekEncryptionAlgorithmread-onlycurrentThe value of the Transform ID field of a PROTO_IPSEC_ESP payload which specifies the ESP transform to be used. If no encryption is used, this value will be zer…
1.3.6.1.4.1.9.9.759.1.3.6.1.5ColumncgmGdoiGmTekEncryptionKeyLengthread-onlycurrentThe length of the key used for encryption in a TEK (in bits).
1.3.6.1.4.1.9.9.759.1.3.6.1.6ColumncgmGdoiGmTekIntegrityAlgorithmread-onlycurrentThe value of the Authentication Algorithm for a TEK IPsec ESP SA. If no authentication is used, this value will be zero (0). Following are the Authentication A…
1.3.6.1.4.1.9.9.759.1.3.6.1.7ColumncgmGdoiGmTekIntegrityKeyLengthread-onlycurrentThe length of the key used for integrity/authentication in a TEK (in bits).
1.3.6.1.4.1.9.9.759.1.3.6.1.8ColumncgmGdoiGmTekWindowSizeread-onlycurrentThe size of the Time Based Anti-Replay (TBAR) window used by this TEK Policy/SA.
1.3.6.1.4.1.9.9.759.1.3.6.1.9ColumncgmGdoiGmTekOriginalLifetimeread-onlycurrentThe value of the SA Life Type defined in RFC 2407 which specifies the maximum time for which a TEK IPsec SA is valid. The GCKS may refresh the TEK at any time …
1.3.6.1.4.1.9.9.759.1.3.6.1.10ColumncgmGdoiGmTekRemainingLifetimeread-onlycurrentThe value of the remaining time for which a TEK is valid. The value is a four (4) octet (32-bit) number which begins at the value of cgmGdoiGmTekOriginalLifeti…
1.3.6.1.4.1.9.9.759.1.3.6.1.11ColumncgmGdoiGmTekStatusread-onlycurrentThe status of the TEK Policy/SA. When this status value is queried, one of the following is returned: inbound(1), outbound(2), notInUse(3).
1.3.6.1.4.1.9.9.759.1.4NodecgmGdoiNotifCntl
1.3.6.1.4.1.9.9.759.1.4.1ScalarcgmGdoiKSNewRegNotifEnableread-writecurrentIndicates whether or not a notification should be generated on a Key Server when a new Group Member begins registration to a GDOI group.
1.3.6.1.4.1.9.9.759.1.4.2ScalarcgmGdoiKSRegCompNotifEnableread-writecurrentIndicates whether or not a notification should be generated on a Key Server when a new Group Member successfully registers to a GDOI group.
1.3.6.1.4.1.9.9.759.1.4.3ScalarcgmGdoiKSRekeyPushNotifEnableread-writecurrentIndicates whether or not a notification should be generated on a Key Server when a rekey is sent to a GDOI group.
1.3.6.1.4.1.9.9.759.1.4.4ScalarcgmGdoiKSNoRSANotifEnableread-writecurrentIndicates whether or not an error notification should be generated on a Key Server when an RSA key is not set up.
1.3.6.1.4.1.9.9.759.1.4.5ScalarcgmGdoiGMRegNotifEnableread-onlycurrentIndicates whether or not a notification should be generated on a Group Member when it starts registration to a Key Server in a GDOI group.
1.3.6.1.4.1.9.9.759.1.4.6ScalarcgmGdoiGmRegCompNotifEnableread-onlycurrentIndicates whether or not a notification should be generated on a Group Member when it successfully registers to a Key Server in a GDOI group.
1.3.6.1.4.1.9.9.759.1.4.7ScalarcgmGdoiGmReRegNotifEnableread-onlycurrentIndicates whether or not a notification should be generated on a Group Member when it starts to re-register to a Key Server in a GDOI group.
1.3.6.1.4.1.9.9.759.1.4.8ScalarcgmGdoiGmRekeyRecNotifEnableread-onlycurrentIndicates whether or not a notification should be generated on a Group Member when it receives and processes a rekey sent by a Key Server in a GDOI group.
1.3.6.1.4.1.9.9.759.1.4.9ScalarcgmGdoiGmIncompCfgNotifEnableread-onlycurrentIndicates whether or not an error notification should be generated on a Group Member when there is missing information for configuring a GDOI group.
1.3.6.1.4.1.9.9.759.1.4.10ScalarcgmGdoiGmNoIpSecFlowsNotifEnableread-onlycurrentIndicates whether or not an error notification should be generated on a Group Member when no more security associations can be installed after receiving a reke…
1.3.6.1.4.1.9.9.759.1.4.11ScalarcgmGdoiGmRekeyFailNotifEnableread-onlycurrentIndicates whether or not an error notification should be generated on a Group Member when it is unable to successfully process and install a rekey.
1.3.6.1.4.1.9.9.759.1.4.12ScalarcgmGdoiKsRoleChangeNotifEnableread-onlycurrentIndicates whether or not cgmGdoiKeyServerRoleChange notification should be generated on a Key Server when its role changes from Primary to Secondary or vice-ve…
1.3.6.1.4.1.9.9.759.1.4.13ScalarcgmGdoiKsGmDeletedNotifEnableread-onlycurrentIndicates whether or not cgmGdoiKeyServerGmDeleted notification should be generated on a Key Server when a Group Member is deleted from the group database.
1.3.6.1.4.1.9.9.759.1.4.14ScalarcgmGdoiKsPeerReachNotifEnableread-onlycurrentIndicates whether or not cgmGdoiKeyServerPeerReachable notification should be generated on a Key Server when unreachable peer Key Server becomes reachable.
1.3.6.1.4.1.9.9.759.1.4.15ScalarcgmGdoiKsPeerUnreachNotifEnableread-onlycurrentIndicates whether or not cgmGdoiKeyServerPeerUnreachable notification should be generated on a Key Server when reachable peer Key Server becomes unreachable.
1.3.6.1.4.1.9.9.759.1.5NodecgmGdoiNotifVars
1.3.6.1.4.1.9.9.759.1.5.1ScalarcgmGdoiNotifGroupIdTypeaccessible-for-notifycurrentVariable used only for notifications. This variable captures the identification type of the GDOI group.
1.3.6.1.4.1.9.9.759.1.5.2ScalarcgmGdoiNotifGroupIdValueaccessible-for-notifycurrentVariable used only for notifications. The value of a Group ID with its type indicated by the cgmGdoiNotifGroupIdType. Use the cgmGdoiNotifGroupIdType to parse …
1.3.6.1.4.1.9.9.759.1.5.3ScalarcgmGdoiNotifGroupNameaccessible-for-notifycurrentVariable used only for notifications. The string-readable name configured for or given to a GDOI Group.
1.3.6.1.4.1.9.9.759.1.5.4ScalarcgmGdoiNotifKeyServerIdTypeaccessible-for-notifycurrentVariable used only for notifications. The Identification Type Value used to parse the identity information of a Key Server.
1.3.6.1.4.1.9.9.759.1.5.5ScalarcgmGdoiNotifKeyServerIdValueaccessible-for-notifycurrentVariable used only for notifications. The value of the identity information for a Key Server with its type indicated by the cgmGdoiNotifKeyServerIdType. Use th…
1.3.6.1.4.1.9.9.759.1.5.6ScalarcgmGdoiNotifKeyServerRoleaccessible-for-notifycurrentVariable used only for notifications. The current role of the Key Server for the Group.
1.3.6.1.4.1.9.9.759.1.5.7ScalarcgmGdoiNotifGmIdTypeaccessible-for-notifycurrentVariable used only for notifications. The Identification Type Value used to parse the identity information for a Initiator or Group Member.
1.3.6.1.4.1.9.9.759.1.5.8ScalarcgmGdoiNotifGmIdValueaccessible-for-notifycurrentVariable used only for notifications. The value of the identity information for a Group Member with its type indicated by the cgmGdoiNotifGmIdType. Use the cgm…
1.3.6.1.4.1.9.9.759.1.5.9ScalarcgmGdoiNotifPeerKsIdTypeaccessible-for-notifycurrentVariable used only for notifications. The Identification Type Value used to parse the identity information of a Key Server.
1.3.6.1.4.1.9.9.759.1.5.10ScalarcgmGdoiNotifPeerKsIdValueaccessible-for-notifycurrentVariable used only for notifications. The value of the identity information for a Peer Key Server with its type indicated by the cgmGdoiNotifPeerKsIdType. Use …
1.3.6.1.4.1.9.9.759.2NodecgmGdoiMIBConformance
1.3.6.1.4.1.9.9.759.2.1NodecgmGdoiMIBGroups
1.3.6.1.4.1.9.9.759.2.1.1GroupcgmGdoiGroupIdGroupcurrentThis group consists of: 1) GDOI Group Table cgmGdoiGroupIdGroupRev1 is an extension to this group.
1.3.6.1.4.1.9.9.759.2.1.2GroupcgmGdoiKeyServerGroupcurrentThis group consists of: 1) GDOI Key Server Table cgmGdoiKeyServerGroupRev1 is an extension to this group.
1.3.6.1.4.1.9.9.759.2.1.3GroupcgmGdoiGmGroupcurrentThis group consists of: 1) GDOI GM Table cgmGdoiGmGroupRev1 is an extension to this group.
1.3.6.1.4.1.9.9.759.2.1.4GroupcgmGdoiKsSecurityAssociationsGroupcurrentThis group consists of: 1) GDOI Key Server KEK Policy/SA Table 2) GDOI Key Server TEK Policy Table
1.3.6.1.4.1.9.9.759.2.1.5GroupcgmGdoiGmSecurityAssociationsGroupcurrentThis group consists of: 1) GDOI Group Member KEK Policy/SA Table 2) GDOI Group Member TEK Policy/SA Table
1.3.6.1.4.1.9.9.759.2.1.6GroupcgmGdoiKeyServerNotificationGroupcurrentThis group contains the Key Server (GCKS) notifications for the GDOI MIB. cgmGdoiKeyServerNotificationGroupRev1 is an extension to this group.
1.3.6.1.4.1.9.9.759.2.1.7GroupcgmGdoiKeyServerErrorNotificationGroupcurrentThis group contains the Key Server (GCKS) error notifications for the GDOI MIB.
1.3.6.1.4.1.9.9.759.2.1.8GroupcgmGdoiGmNotificationGroupcurrentThis group contains the Group Member (GM) notifications for the GDOI MIB.
1.3.6.1.4.1.9.9.759.2.1.9GroupcgmGdoiGmErrorNotificationGroupcurrentThis group contains the Group Member (GM) error notifications for the GDOI MIB.
1.3.6.1.4.1.9.9.759.2.1.10GroupcgmGdoiNotificationControlGroupcurrentThis group contains the GDOI notification control objects for the GDOI MIB. cgmGdoiNotificationControlGroupRev1 is an extension to this group.
1.3.6.1.4.1.9.9.759.2.1.11GroupcgmGdoiGroupIdGroupRev1currentThis group consists of: 1) GDOI Group Table This group is an extension to cgmGdoiGroupIdGroup.
1.3.6.1.4.1.9.9.759.2.1.12GroupcgmGdoiKeyServerGroupRev1currentThis group consists of: 1) GDOI Key Server Table This group is an extension to cgmGdoiKeyServerGroup.
1.3.6.1.4.1.9.9.759.2.1.13GroupcgmGdoiGmGroupRev1currentThis group consists of: 1) GDOI GM Table This group is an extension to cgmGdoiGmGroup.
1.3.6.1.4.1.9.9.759.2.1.14GroupcgmGdoiKeyServerNotificationGroupRev1currentThis group contains the Key Server (GCKS) notifications for the GDOI MIB. This group is an extension to cgmGdoiKeyServerNotificationGroup.
1.3.6.1.4.1.9.9.759.2.1.15GroupcgmGdoiNotificationControlGroupRev1currentThis group contains the GDOI notification control objects for the GDOI MIB. This group is an extension to cgmGdoiNotificationControlGroup.
1.3.6.1.4.1.9.9.759.2.1.16GroupcgmGdoiCoopPeerGroupcurrentThis group consists of: 1) COOP Peer Key Server Table
1.3.6.1.4.1.9.9.759.2.1.17GroupcgmGdoiNotificationVariablesGroupcurrentThis group contains the GDOI notification variables for the GDOI MIB.
1.3.6.1.4.1.9.9.759.2.2NodecgmGdoiMIBCompliances
1.3.6.1.4.1.9.9.759.2.2.1CompliancecgmGdoiMIBCompliancedeprecatedAt minimum, only GDOI Group Member functionality is required so only objects associated with and needed by Group Members are mandatory to implement. If Key Ser…
1.3.6.1.4.1.9.9.759.2.2.2CompliancecgmGdoiMIBComplianceRev1read-onlycurrentAt minimum, only GDOI Group Member functionality is required so only objects associated with and needed by Group Members are mandatory to implement. If Key Ser…
Type Definitions
NameSyntaxStatusDescription
CgmGdoiDiffieHellmanGroupINTEGER { dhNone(0), dhGroup1(1), dhGroup2(2), dhEc2nGp155(3), dhEc2nGp185(4), dh1536Modp(5), dh2048Modp(14), dh3072Modp(15), dh4096Modp(16), dh6144Modp(17), dh8192Modp(18), dhEcp256(19), dhEcp84(20), dhEcp521(21), dh1024Modp160(22), dh2048Modp224(23), dh2048Modp256(24), dhEcp192(25), dhEcp224(26) }currentA textual convention indicating the identifier of the Diffie-Hellman Group being used. Following are the possible updated Diffie-Hellman Group values & CgmGdoiDiffieHellmanGroup mappings after RFC 4306: Diffie-Hellman G…
CgmGdoiEncapsulationModeINTEGER { encapUnknown(0), encapTunnel(1), encapTransport(2), encapUdpTunnel(3), encapUdpTransport(4) }currentA textual convention indicating the identifier of the Encapsulation Mode being used. Following are the possible Encapsulation Mode values & CgmGdoiEncapsulationMode mappings from RFC 2407: Encapsulation Mode Value Tunne…
CgmGdoiEncryptionAlgorithmINTEGER { encrAlgNone(0), encrAlgDes64(1), encrAlgDes(2), encrAlg3Des(3), encrAlgRc5(4), encrAlgIdea(5), encrAlgCast(6), encrAlgBlowfish(7), encrAlg3Idea(8), encrAlgDes32(9), encrAlgRc4(10), encrAlgNull(11), encrAlgAesCbc(12), encrAlgAesCtr(13), encrAlgAesCcm8(14), encrAlgAesCcm12(15), encrAlgAesCcm16(16), encrAlgAesGcm8(18), encrAlgAesGcm12(19), encrAlgAesGcm16(20), encrAlgNullAuthAesGmac(21), encrAlgCamelliaCbc(23), encrAlgCamelliaCtr(24), encrAlgCamelliaCcm8(25), encrAlgCamelliaCcm12(26), encrAlgCamelliaCcm1(27), encrAlgSeedCbc(28) }currentA textual convention indicating the identifier of the encryption algorithm being used. Following are the possible updated encryption algorithm values & CgmGdoiEncryptionAlgorithm mappings after RFC 4306: Encryption Algo…
CgmGdoiIdentificationTypeINTEGER { ipv4Address(1), domainName(2), userName(3), ipv4Subnet(4), ipv6Address(5), ipv6Subnet(6), ipv4Range(7), ipv6Range(8), caDistinguishedName(9), caGeneralName(10), groupNumber(11) }currentA textual convention indicating the type of value used to identify a GDOI entity (i.e. Group, Key Server, or Group Member). Following are the Identification Type Values: ID Type Value RESERVED 0 ID_IPV4_ADDR 1 ID_FQDN 2…
CgmGdoiIdentificationValueOCTET STRING (SIZE (0..48))currentA textual convention indicating the actual value of used to identify a GDOI entity (i.e. Group, Key Server, or Group Member). The value of the CgmGdoiIdentificationValue object can be parsed based on the value of the as…
CgmGdoiIntegrityAlgorithmINTEGER { authAlgNone(0), authAlgMd5Hmac96(1), authAlgSha1Hmac96(2), authAlgDesMac(3), authAlgMd5Kpdk(4), authAlgAesXcbc96(5), authAlgMd5Hmac128(6), authAlgSha1Hmac160(7), authAlgAesCmac96(8), authAlgAes128Gmac(9), authAlgAes192Gmac(10), authAlgAes256Gmac(11), authAlgSha2Hmac256to128(12), authAlgSha2Hmac384to192(13), authAlgSha2Hmac512to256(14) }currentA textual convention indicating the identifier of the integirty algorithm being used. Following are the possible updated integrity algorithm values & CgmGdoiIntegrityAlgorithm mappings after RFC 4306: Integrity Algorith…
CgmGdoiIpProtocolIdINTEGER { ipProtocolUnknown(0), ipProtocolTCP(1), ipProtocolUDP(2) }currentA textual convention indicating the identifier of the IP Protocol being used for the rekey datagram. Some possible values are: ID Value ID Type 06 TCP 17 UDP REFERENCE
CgmGdoiKekSPIOCTET STRING (SIZE (16))currentA textual convention indicating a SPI (Security Parameter Index) of sixteen (16) octets for a KEK. The SPI must be the ISAKMP Header cookie pair where the first 8 octets become the 'Initiator Cookie' field of the GROUPK…
CgmGdoiKekStatusINTEGER { inUse(1), new(2), old(3) }currentA textual convention indicating the status of a GDOI KEK and its corresponding Security Association (SA). 'inUse' : KEK currently being used to encrypt new KEK/TEKs 'new' : KEK currently being sent to all peers 'old' : …
CgmGdoiKeyManagementAlgorithmINTEGER { keyMgmtNone(0), keyMgmtLkh(1) }currentA textual convention indicating the identifier of the key/KEK management algorithm being used to provide forward or backward access control (i.e. used to exclude group members). Following are the possible KEK management…
CgmGdoiKsRoleINTEGER { keyServerPrimary(1), keyServerSecondary(2), keyServerUnknown(3) }current
CgmGdoiKsStatusINTEGER { keyServerAlive(1), keyServerDead(2), keyServerUnknown(3) }currentA textual convention identifying the status of Key Server in the COOP/Stand-alone scenario. Following are the possible values: ID Type Value Alive 1 Dead 2 Unknown 3 or, the status of a secondary peer when seen from a S…
CgmGdoiPseudoRandomFunctionINTEGER { prfNone(0), prfMd5Hmac(1), prfSha1Hmac(2), prfTigerHmac(3), prfAes128Xcbc(4), prfSha2Hmac256(5), prfSha2Hmac384(6), prfSha2Hmac512(7), prfAes128Cmac(8) }currentA textual convention indicating the identifier of the pseudo-random function (PRF) being used. Following are the possible updated PRF values & CgmGdoiPseudoRandomFunction mappings after RFC 4306: Pseudo-Random Function …
CgmGdoiSecurityProtocolINTEGER { secProtocolUnknown(0), secProtocolIpsecEsp(1) }currentA textual convention indicating the identifier of the Security Protocol being used. Following are the possible Security Protocol ID values & CgmGdoiSecurityProtocol mappings from the GDOI RFC 3547: Security Protocol ID …
CgmGdoiSignatureMethodINTEGER { sigNone(0), sigRsa(1), sigSharedKey(2), sigDss(3), sigEncryptRsa(4), sigRevEncryptRsa(5), sigEcdsa256(9), sigEcdsa384(10), sigEcdsa512(11) }currentA textual convention indicating the identifier of the integirty algorithm being used. Following are the possible updated authentication method values & CgmGdoiSignatureMethod mappings after RFC 4306: Authentication Meth…
CgmGdoiTekSPIOCTET STRING (SIZE (4))currentA textual convention indicating a SPI (Security Parameter Index) of four (4) octets for a TEK using ESP.
CgmGdoiTekStatusINTEGER { inbound(1), outbound(2), notInUse(3) }currentA textual convention indicating the status of a GDOI TEK and its corresponding Security Association (SA). 'inbound' : TEK is being used as inbound (receive) SA 'outbound' : TEK is being used as outbound (transmit) SA 'n…
CgmGdoiUnsigned16OCTET STRING (SIZE (2))currentA textual convention indicating a 16-bit unsigned integer value.