SNMP-TLS-TM-MIB.txt 43 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066
  1. SNMP-TLS-TM-MIB DEFINITIONS ::= BEGIN
  2. IMPORTS
  3. MODULE-IDENTITY, OBJECT-TYPE,
  4. OBJECT-IDENTITY, mib-2, snmpDomains,
  5. Counter32, Unsigned32, Gauge32, NOTIFICATION-TYPE
  6. FROM SNMPv2-SMI -- RFC 2578 or any update thereof
  7. TEXTUAL-CONVENTION, TimeStamp, RowStatus, StorageType,
  8. AutonomousType
  9. FROM SNMPv2-TC -- RFC 2579 or any update thereof
  10. MODULE-COMPLIANCE, OBJECT-GROUP, NOTIFICATION-GROUP
  11. FROM SNMPv2-CONF -- RFC 2580 or any update thereof
  12. SnmpAdminString
  13. FROM SNMP-FRAMEWORK-MIB -- RFC 3411 or any update thereof
  14. snmpTargetParamsName, snmpTargetAddrName
  15. FROM SNMP-TARGET-MIB -- RFC 3413 or any update thereof
  16. ;
  17. snmpTlstmMIB MODULE-IDENTITY
  18. LAST-UPDATED "201107190000Z"
  19. ORGANIZATION "ISMS Working Group"
  20. CONTACT-INFO "WG-EMail: isms@lists.ietf.org
  21. Subscribe: isms-request@lists.ietf.org
  22. Chairs:
  23. Juergen Schoenwaelder
  24. Jacobs University Bremen
  25. Campus Ring 1
  26. 28725 Bremen
  27. Germany
  28. +49 421 200-3587
  29. j.schoenwaelder@jacobs-university.de
  30. Russ Mundy
  31. SPARTA, Inc.
  32. 7110 Samuel Morse Drive
  33. Columbia, MD 21046
  34. USA
  35. Editor:
  36. Wes Hardaker
  37. SPARTA, Inc.
  38. P.O. Box 382
  39. Davis, CA 95617
  40. USA
  41. ietf@hardakers.net
  42. "
  43. DESCRIPTION "
  44. The TLS Transport Model MIB
  45. Copyright (c) 2010-2011 IETF Trust and the persons identified
  46. as authors of the code. All rights reserved.
  47. Redistribution and use in source and binary forms, with or
  48. without modification, is permitted pursuant to, and subject
  49. to the license terms contained in, the Simplified BSD License
  50. set forth in Section 4.c of the IETF Trust's Legal Provisions
  51. Relating to IETF Documents
  52. (http://trustee.ietf.org/license-info)."
  53. REVISION "201107190000Z"
  54. DESCRIPTION "This version of this MIB module is part of
  55. RFC 6353; see the RFC itself for full legal
  56. notices. The only change was to introduce
  57. new wording to reflect require changes for
  58. IDNA addresses in the SnmpTLSAddress TC."
  59. REVISION "201005070000Z"
  60. DESCRIPTION "This version of this MIB module is part of
  61. RFC 5953; see the RFC itself for full legal
  62. notices."
  63. ::= { mib-2 198 }
  64. -- ************************************************
  65. -- subtrees of the SNMP-TLS-TM-MIB
  66. -- ************************************************
  67. snmpTlstmNotifications OBJECT IDENTIFIER ::= { snmpTlstmMIB 0 }
  68. snmpTlstmIdentities OBJECT IDENTIFIER ::= { snmpTlstmMIB 1 }
  69. snmpTlstmObjects OBJECT IDENTIFIER ::= { snmpTlstmMIB 2 }
  70. snmpTlstmConformance OBJECT IDENTIFIER ::= { snmpTlstmMIB 3 }
  71. -- ************************************************
  72. -- snmpTlstmObjects - Objects
  73. -- ************************************************
  74. snmpTLSTCPDomain OBJECT-IDENTITY
  75. STATUS current
  76. DESCRIPTION
  77. "The SNMP over TLS via TCP transport domain. The
  78. corresponding transport address is of type SnmpTLSAddress.
  79. The securityName prefix to be associated with the
  80. snmpTLSTCPDomain is 'tls'. This prefix may be used by
  81. security models or other components to identify which secure
  82. transport infrastructure authenticated a securityName."
  83. REFERENCE
  84. "RFC 2579: Textual Conventions for SMIv2"
  85. ::= { snmpDomains 8 }
  86. snmpDTLSUDPDomain OBJECT-IDENTITY
  87. STATUS current
  88. DESCRIPTION
  89. "The SNMP over DTLS via UDP transport domain. The
  90. corresponding transport address is of type SnmpTLSAddress.
  91. The securityName prefix to be associated with the
  92. snmpDTLSUDPDomain is 'dtls'. This prefix may be used by
  93. security models or other components to identify which secure
  94. transport infrastructure authenticated a securityName."
  95. REFERENCE
  96. "RFC 2579: Textual Conventions for SMIv2"
  97. ::= { snmpDomains 9 }
  98. SnmpTLSAddress ::= TEXTUAL-CONVENTION
  99. DISPLAY-HINT "1a"
  100. STATUS current
  101. DESCRIPTION
  102. "Represents an IPv4 address, an IPv6 address, or a
  103. US-ASCII-encoded hostname and port number.
  104. An IPv4 address must be in dotted decimal format followed by a
  105. colon ':' (US-ASCII character 0x3A) and a decimal port number
  106. in US-ASCII.
  107. An IPv6 address must be a colon-separated format (as described
  108. in RFC 5952), surrounded by square brackets ('[', US-ASCII
  109. character 0x5B, and ']', US-ASCII character 0x5D), followed by
  110. a colon ':' (US-ASCII character 0x3A) and a decimal port number
  111. in US-ASCII.
  112. A hostname is always in US-ASCII (as per RFC 1123);
  113. internationalized hostnames are encoded as A-labels as specified
  114. in RFC 5890. The hostname is followed by a
  115. colon ':' (US-ASCII character 0x3A) and a decimal port number
  116. in US-ASCII. The name SHOULD be fully qualified whenever
  117. possible.
  118. Values of this textual convention may not be directly usable
  119. as transport-layer addressing information, and may require
  120. run-time resolution. As such, applications that write them
  121. must be prepared for handling errors if such values are not
  122. supported, or cannot be resolved (if resolution occurs at the
  123. time of the management operation).
  124. The DESCRIPTION clause of TransportAddress objects that may
  125. have SnmpTLSAddress values must fully describe how (and
  126. when) such names are to be resolved to IP addresses and vice
  127. versa.
  128. This textual convention SHOULD NOT be used directly in object
  129. definitions since it restricts addresses to a specific
  130. format. However, if it is used, it MAY be used either on its
  131. own or in conjunction with TransportAddressType or
  132. TransportDomain as a pair.
  133. When this textual convention is used as a syntax of an index
  134. object, there may be issues with the limit of 128
  135. sub-identifiers specified in SMIv2 (STD 58). It is RECOMMENDED
  136. that all MIB documents using this textual convention make
  137. explicit any limitations on index component lengths that
  138. management software must observe. This may be done either by
  139. including SIZE constraints on the index components or by
  140. specifying applicable constraints in the conceptual row
  141. DESCRIPTION clause or in the surrounding documentation."
  142. REFERENCE
  143. "RFC 1123: Requirements for Internet Hosts - Application and
  144. Support
  145. RFC 5890: Internationalized Domain Names for Applications (IDNA):
  146. Definitions and Document Framework
  147. RFC 5952: A Recommendation for IPv6 Address Text Representation
  148. "
  149. SYNTAX OCTET STRING (SIZE (1..255))
  150. SnmpTLSFingerprint ::= TEXTUAL-CONVENTION
  151. DISPLAY-HINT "1x:1x"
  152. STATUS current
  153. DESCRIPTION
  154. "A fingerprint value that can be used to uniquely reference
  155. other data of potentially arbitrary length.
  156. An SnmpTLSFingerprint value is composed of a 1-octet hashing
  157. algorithm identifier followed by the fingerprint value. The
  158. octet value encoded is taken from the IANA TLS HashAlgorithm
  159. Registry (RFC 5246). The remaining octets are filled using the
  160. results of the hashing algorithm.
  161. This TEXTUAL-CONVENTION allows for a zero-length (blank)
  162. SnmpTLSFingerprint value for use in tables where the
  163. fingerprint value may be optional. MIB definitions or
  164. implementations may refuse to accept a zero-length value as
  165. appropriate."
  166. REFERENCE "RFC 5246: The Transport Layer
  167. Security (TLS) Protocol Version 1.2
  168. http://www.iana.org/assignments/tls-parameters/
  169. "
  170. SYNTAX OCTET STRING (SIZE (0..255))
  171. -- Identities for use in the snmpTlstmCertToTSNTable
  172. snmpTlstmCertToTSNMIdentities OBJECT IDENTIFIER
  173. ::= { snmpTlstmIdentities 1 }
  174. snmpTlstmCertSpecified OBJECT-IDENTITY
  175. STATUS current
  176. DESCRIPTION "Directly specifies the tmSecurityName to be used for
  177. this certificate. The value of the tmSecurityName
  178. to use is specified in the snmpTlstmCertToTSNData
  179. column. The snmpTlstmCertToTSNData column must
  180. contain a non-zero length SnmpAdminString compliant
  181. value or the mapping described in this row must be
  182. considered a failure."
  183. ::= { snmpTlstmCertToTSNMIdentities 1 }
  184. snmpTlstmCertSANRFC822Name OBJECT-IDENTITY
  185. STATUS current
  186. DESCRIPTION "Maps a subjectAltName's rfc822Name to a
  187. tmSecurityName. The local part of the rfc822Name is
  188. passed unaltered but the host-part of the name must
  189. be passed in lowercase. This mapping results in a
  190. 1:1 correspondence between equivalent subjectAltName
  191. rfc822Name values and tmSecurityName values except
  192. that the host-part of the name MUST be passed in
  193. lowercase.
  194. Example rfc822Name Field: FooBar@Example.COM
  195. is mapped to tmSecurityName: FooBar@example.com."
  196. ::= { snmpTlstmCertToTSNMIdentities 2 }
  197. snmpTlstmCertSANDNSName OBJECT-IDENTITY
  198. STATUS current
  199. DESCRIPTION "Maps a subjectAltName's dNSName to a
  200. tmSecurityName after first converting it to all
  201. lowercase (RFC 5280 does not specify converting to
  202. lowercase so this involves an extra step). This
  203. mapping results in a 1:1 correspondence between
  204. subjectAltName dNSName values and the tmSecurityName
  205. values."
  206. REFERENCE "RFC 5280 - Internet X.509 Public Key Infrastructure
  207. Certificate and Certificate Revocation
  208. List (CRL) Profile."
  209. ::= { snmpTlstmCertToTSNMIdentities 3 }
  210. snmpTlstmCertSANIpAddress OBJECT-IDENTITY
  211. STATUS current
  212. DESCRIPTION "Maps a subjectAltName's iPAddress to a
  213. tmSecurityName by transforming the binary encoded
  214. address as follows:
  215. 1) for IPv4, the value is converted into a
  216. decimal-dotted quad address (e.g., '192.0.2.1').
  217. 2) for IPv6 addresses, the value is converted into a
  218. 32-character all lowercase hexadecimal string
  219. without any colon separators.
  220. This mapping results in a 1:1 correspondence between
  221. subjectAltName iPAddress values and the
  222. tmSecurityName values.
  223. The resulting length of an encoded IPv6 address is
  224. the maximum length supported by the View-Based
  225. Access Control Model (VACM). Using both the
  226. Transport Security Model's support for transport
  227. prefixes (see the SNMP-TSM-MIB's
  228. snmpTsmConfigurationUsePrefix object for details)
  229. will result in securityName lengths that exceed what
  230. VACM can handle."
  231. ::= { snmpTlstmCertToTSNMIdentities 4 }
  232. snmpTlstmCertSANAny OBJECT-IDENTITY
  233. STATUS current
  234. DESCRIPTION "Maps any of the following fields using the
  235. corresponding mapping algorithms:
  236. |------------+----------------------------|
  237. | Type | Algorithm |
  238. |------------+----------------------------|
  239. | rfc822Name | snmpTlstmCertSANRFC822Name |
  240. | dNSName | snmpTlstmCertSANDNSName |
  241. | iPAddress | snmpTlstmCertSANIpAddress |
  242. |------------+----------------------------|
  243. The first matching subjectAltName value found in the
  244. certificate of the above types MUST be used when
  245. deriving the tmSecurityName. The mapping algorithm
  246. specified in the 'Algorithm' column MUST be used to
  247. derive the tmSecurityName.
  248. This mapping results in a 1:1 correspondence between
  249. subjectAltName values and tmSecurityName values. The
  250. three sub-mapping algorithms produced by this
  251. combined algorithm cannot produce conflicting
  252. results between themselves."
  253. ::= { snmpTlstmCertToTSNMIdentities 5 }
  254. snmpTlstmCertCommonName OBJECT-IDENTITY
  255. STATUS current
  256. DESCRIPTION "Maps a certificate's CommonName to a tmSecurityName
  257. after converting it to a UTF-8 encoding. The usage
  258. of CommonNames is deprecated and users are
  259. encouraged to use subjectAltName mapping methods
  260. instead. This mapping results in a 1:1
  261. correspondence between certificate CommonName values
  262. and tmSecurityName values."
  263. ::= { snmpTlstmCertToTSNMIdentities 6 }
  264. -- The snmpTlstmSession Group
  265. snmpTlstmSession OBJECT IDENTIFIER ::= { snmpTlstmObjects 1 }
  266. snmpTlstmSessionOpens OBJECT-TYPE
  267. SYNTAX Counter32
  268. MAX-ACCESS read-only
  269. STATUS current
  270. DESCRIPTION
  271. "The number of times an openSession() request has been executed
  272. as a (D)TLS client, regardless of whether it succeeded or
  273. failed."
  274. ::= { snmpTlstmSession 1 }
  275. snmpTlstmSessionClientCloses OBJECT-TYPE
  276. SYNTAX Counter32
  277. MAX-ACCESS read-only
  278. STATUS current
  279. DESCRIPTION
  280. "The number of times a closeSession() request has been
  281. executed as a (D)TLS client, regardless of whether it
  282. succeeded or failed."
  283. ::= { snmpTlstmSession 2 }
  284. snmpTlstmSessionOpenErrors OBJECT-TYPE
  285. SYNTAX Counter32
  286. MAX-ACCESS read-only
  287. STATUS current
  288. DESCRIPTION
  289. "The number of times an openSession() request failed to open a
  290. session as a (D)TLS client, for any reason."
  291. ::= { snmpTlstmSession 3 }
  292. snmpTlstmSessionAccepts OBJECT-TYPE
  293. SYNTAX Counter32
  294. MAX-ACCESS read-only
  295. STATUS current
  296. DESCRIPTION
  297. "The number of times a (D)TLS server has accepted a new
  298. connection from a client and has received at least one SNMP
  299. message through it."
  300. ::= { snmpTlstmSession 4 }
  301. snmpTlstmSessionServerCloses OBJECT-TYPE
  302. SYNTAX Counter32
  303. MAX-ACCESS read-only
  304. STATUS current
  305. DESCRIPTION
  306. "The number of times a closeSession() request has been
  307. executed as a (D)TLS server, regardless of whether it
  308. succeeded or failed."
  309. ::= { snmpTlstmSession 5 }
  310. snmpTlstmSessionNoSessions OBJECT-TYPE
  311. SYNTAX Counter32
  312. MAX-ACCESS read-only
  313. STATUS current
  314. DESCRIPTION
  315. "The number of times an outgoing message was dropped because
  316. the session associated with the passed tmStateReference was no
  317. longer (or was never) available."
  318. ::= { snmpTlstmSession 6 }
  319. snmpTlstmSessionInvalidClientCertificates OBJECT-TYPE
  320. SYNTAX Counter32
  321. MAX-ACCESS read-only
  322. STATUS current
  323. DESCRIPTION
  324. "The number of times an incoming session was not established
  325. on a (D)TLS server because the presented client certificate
  326. was invalid. Reasons for invalidation include, but are not
  327. limited to, cryptographic validation failures or lack of a
  328. suitable mapping row in the snmpTlstmCertToTSNTable."
  329. ::= { snmpTlstmSession 7 }
  330. snmpTlstmSessionUnknownServerCertificate OBJECT-TYPE
  331. SYNTAX Counter32
  332. MAX-ACCESS read-only
  333. STATUS current
  334. DESCRIPTION
  335. "The number of times an outgoing session was not established
  336. on a (D)TLS client because the server certificate presented
  337. by an SNMP over (D)TLS server was invalid because no
  338. configured fingerprint or Certification Authority (CA) was
  339. acceptable to validate it.
  340. This may result because there was no entry in the
  341. snmpTlstmAddrTable or because no path could be found to a
  342. known CA."
  343. ::= { snmpTlstmSession 8 }
  344. snmpTlstmSessionInvalidServerCertificates OBJECT-TYPE
  345. SYNTAX Counter32
  346. MAX-ACCESS read-only
  347. STATUS current
  348. DESCRIPTION
  349. "The number of times an outgoing session was not established
  350. on a (D)TLS client because the server certificate presented
  351. by an SNMP over (D)TLS server could not be validated even if
  352. the fingerprint or expected validation path was known. That
  353. is, a cryptographic validation error occurred during
  354. certificate validation processing.
  355. Reasons for invalidation include, but are not
  356. limited to, cryptographic validation failures."
  357. ::= { snmpTlstmSession 9 }
  358. snmpTlstmSessionInvalidCaches OBJECT-TYPE
  359. SYNTAX Counter32
  360. MAX-ACCESS read-only
  361. STATUS current
  362. DESCRIPTION
  363. "The number of outgoing messages dropped because the
  364. tmStateReference referred to an invalid cache."
  365. ::= { snmpTlstmSession 10 }
  366. -- Configuration Objects
  367. snmpTlstmConfig OBJECT IDENTIFIER ::= { snmpTlstmObjects 2 }
  368. -- Certificate mapping
  369. snmpTlstmCertificateMapping OBJECT IDENTIFIER ::= { snmpTlstmConfig 1 }
  370. snmpTlstmCertToTSNCount OBJECT-TYPE
  371. SYNTAX Gauge32
  372. MAX-ACCESS read-only
  373. STATUS current
  374. DESCRIPTION
  375. "A count of the number of entries in the
  376. snmpTlstmCertToTSNTable."
  377. ::= { snmpTlstmCertificateMapping 1 }
  378. snmpTlstmCertToTSNTableLastChanged OBJECT-TYPE
  379. SYNTAX TimeStamp
  380. MAX-ACCESS read-only
  381. STATUS current
  382. DESCRIPTION
  383. "The value of sysUpTime.0 when the snmpTlstmCertToTSNTable was
  384. last modified through any means, or 0 if it has not been
  385. modified since the command responder was started."
  386. ::= { snmpTlstmCertificateMapping 2 }
  387. snmpTlstmCertToTSNTable OBJECT-TYPE
  388. SYNTAX SEQUENCE OF SnmpTlstmCertToTSNEntry
  389. MAX-ACCESS not-accessible
  390. STATUS current
  391. DESCRIPTION
  392. "This table is used by a (D)TLS server to map the (D)TLS
  393. client's presented X.509 certificate to a tmSecurityName.
  394. On an incoming (D)TLS/SNMP connection, the client's presented
  395. certificate must either be validated based on an established
  396. trust anchor, or it must directly match a fingerprint in this
  397. table. This table does not provide any mechanisms for
  398. configuring the trust anchors; the transfer of any needed
  399. trusted certificates for path validation is expected to occur
  400. through an out-of-band transfer.
  401. Once the certificate has been found acceptable (either by path
  402. validation or directly matching a fingerprint in this table),
  403. this table is consulted to determine the appropriate
  404. tmSecurityName to identify with the remote connection. This
  405. is done by considering each active row from this table in
  406. prioritized order according to its snmpTlstmCertToTSNID value.
  407. Each row's snmpTlstmCertToTSNFingerprint value determines
  408. whether the row is a match for the incoming connection:
  409. 1) If the row's snmpTlstmCertToTSNFingerprint value
  410. identifies the presented certificate, then consider the
  411. row as a successful match.
  412. 2) If the row's snmpTlstmCertToTSNFingerprint value
  413. identifies a locally held copy of a trusted CA
  414. certificate and that CA certificate was used to
  415. validate the path to the presented certificate, then
  416. consider the row as a successful match.
  417. Once a matching row has been found, the
  418. snmpTlstmCertToTSNMapType value can be used to determine how
  419. the tmSecurityName to associate with the session should be
  420. determined. See the snmpTlstmCertToTSNMapType column's
  421. DESCRIPTION for details on determining the tmSecurityName
  422. value. If it is impossible to determine a tmSecurityName from
  423. the row's data combined with the data presented in the
  424. certificate, then additional rows MUST be searched looking for
  425. another potential match. If a resulting tmSecurityName mapped
  426. from a given row is not compatible with the needed
  427. requirements of a tmSecurityName (e.g., VACM imposes a
  428. 32-octet-maximum length and the certificate derived
  429. securityName could be longer), then it must be considered an
  430. invalid match and additional rows MUST be searched looking for
  431. another potential match.
  432. If no matching and valid row can be found, the connection MUST
  433. be closed and SNMP messages MUST NOT be accepted over it.
  434. Missing values of snmpTlstmCertToTSNID are acceptable and
  435. implementations should continue to the next highest numbered
  436. row. It is recommended that administrators skip index values
  437. to leave room for the insertion of future rows (for example,
  438. use values of 10 and 20 when creating initial rows).
  439. Users are encouraged to make use of certificates with
  440. subjectAltName fields that can be used as tmSecurityNames so
  441. that a single root CA certificate can allow all child
  442. certificate's subjectAltName to map directly to a
  443. tmSecurityName via a 1:1 transformation. However, this table
  444. is flexible to allow for situations where existing deployed
  445. certificate infrastructures do not provide adequate
  446. subjectAltName values for use as tmSecurityNames.
  447. Certificates may also be mapped to tmSecurityNames using the
  448. CommonName portion of the Subject field. However, the usage
  449. of the CommonName field is deprecated and thus this usage is
  450. NOT RECOMMENDED. Direct mapping from each individual
  451. certificate fingerprint to a tmSecurityName is also possible
  452. but requires one entry in the table per tmSecurityName and
  453. requires more management operations to completely configure a
  454. device."
  455. ::= { snmpTlstmCertificateMapping 3 }
  456. snmpTlstmCertToTSNEntry OBJECT-TYPE
  457. SYNTAX SnmpTlstmCertToTSNEntry
  458. MAX-ACCESS not-accessible
  459. STATUS current
  460. DESCRIPTION
  461. "A row in the snmpTlstmCertToTSNTable that specifies a mapping
  462. for an incoming (D)TLS certificate to a tmSecurityName to use
  463. for a connection."
  464. INDEX { snmpTlstmCertToTSNID }
  465. ::= { snmpTlstmCertToTSNTable 1 }
  466. SnmpTlstmCertToTSNEntry ::= SEQUENCE {
  467. snmpTlstmCertToTSNID Unsigned32,
  468. snmpTlstmCertToTSNFingerprint SnmpTLSFingerprint,
  469. snmpTlstmCertToTSNMapType AutonomousType,
  470. snmpTlstmCertToTSNData OCTET STRING,
  471. snmpTlstmCertToTSNStorageType StorageType,
  472. snmpTlstmCertToTSNRowStatus RowStatus
  473. }
  474. snmpTlstmCertToTSNID OBJECT-TYPE
  475. SYNTAX Unsigned32 (1..4294967295)
  476. MAX-ACCESS not-accessible
  477. STATUS current
  478. DESCRIPTION
  479. "A unique, prioritized index for the given entry. Lower
  480. numbers indicate a higher priority."
  481. ::= { snmpTlstmCertToTSNEntry 1 }
  482. snmpTlstmCertToTSNFingerprint OBJECT-TYPE
  483. SYNTAX SnmpTLSFingerprint (SIZE(1..255))
  484. MAX-ACCESS read-create
  485. STATUS current
  486. DESCRIPTION
  487. "A cryptographic hash of an X.509 certificate. The results of
  488. a successful matching fingerprint to either the trusted CA in
  489. the certificate validation path or to the certificate itself
  490. is dictated by the snmpTlstmCertToTSNMapType column."
  491. ::= { snmpTlstmCertToTSNEntry 2 }
  492. snmpTlstmCertToTSNMapType OBJECT-TYPE
  493. SYNTAX AutonomousType
  494. MAX-ACCESS read-create
  495. STATUS current
  496. DESCRIPTION
  497. "Specifies the mapping type for deriving a tmSecurityName from
  498. a certificate. Details for mapping of a particular type SHALL
  499. be specified in the DESCRIPTION clause of the OBJECT-IDENTITY
  500. that describes the mapping. If a mapping succeeds it will
  501. return a tmSecurityName for use by the TLSTM model and
  502. processing stops.
  503. If the resulting mapped value is not compatible with the
  504. needed requirements of a tmSecurityName (e.g., VACM imposes a
  505. 32-octet-maximum length and the certificate derived
  506. securityName could be longer), then future rows MUST be
  507. searched for additional snmpTlstmCertToTSNFingerprint matches
  508. to look for a mapping that succeeds.
  509. Suitable values for assigning to this object that are defined
  510. within the SNMP-TLS-TM-MIB can be found in the
  511. snmpTlstmCertToTSNMIdentities portion of the MIB tree."
  512. DEFVAL { snmpTlstmCertSpecified }
  513. ::= { snmpTlstmCertToTSNEntry 3 }
  514. snmpTlstmCertToTSNData OBJECT-TYPE
  515. SYNTAX OCTET STRING (SIZE(0..1024))
  516. MAX-ACCESS read-create
  517. STATUS current
  518. DESCRIPTION
  519. "Auxiliary data used as optional configuration information for
  520. a given mapping specified by the snmpTlstmCertToTSNMapType
  521. column. Only some mapping systems will make use of this
  522. column. The value in this column MUST be ignored for any
  523. mapping type that does not require data present in this
  524. column."
  525. DEFVAL { "" }
  526. ::= { snmpTlstmCertToTSNEntry 4 }
  527. snmpTlstmCertToTSNStorageType OBJECT-TYPE
  528. SYNTAX StorageType
  529. MAX-ACCESS read-create
  530. STATUS current
  531. DESCRIPTION
  532. "The storage type for this conceptual row. Conceptual rows
  533. having the value 'permanent' need not allow write-access to
  534. any columnar objects in the row."
  535. DEFVAL { nonVolatile }
  536. ::= { snmpTlstmCertToTSNEntry 5 }
  537. snmpTlstmCertToTSNRowStatus OBJECT-TYPE
  538. SYNTAX RowStatus
  539. MAX-ACCESS read-create
  540. STATUS current
  541. DESCRIPTION
  542. "The status of this conceptual row. This object may be used
  543. to create or remove rows from this table.
  544. To create a row in this table, an administrator must set this
  545. object to either createAndGo(4) or createAndWait(5).
  546. Until instances of all corresponding columns are appropriately
  547. configured, the value of the corresponding instance of the
  548. snmpTlstmParamsRowStatus column is notReady(3).
  549. In particular, a newly created row cannot be made active until
  550. the corresponding snmpTlstmCertToTSNFingerprint,
  551. snmpTlstmCertToTSNMapType, and snmpTlstmCertToTSNData columns
  552. have been set.
  553. The following objects may not be modified while the
  554. value of this object is active(1):
  555. - snmpTlstmCertToTSNFingerprint
  556. - snmpTlstmCertToTSNMapType
  557. - snmpTlstmCertToTSNData
  558. An attempt to set these objects while the value of
  559. snmpTlstmParamsRowStatus is active(1) will result in
  560. an inconsistentValue error."
  561. ::= { snmpTlstmCertToTSNEntry 6 }
  562. -- Maps tmSecurityNames to certificates for use by the SNMP-TARGET-MIB
  563. snmpTlstmParamsCount OBJECT-TYPE
  564. SYNTAX Gauge32
  565. MAX-ACCESS read-only
  566. STATUS current
  567. DESCRIPTION
  568. "A count of the number of entries in the snmpTlstmParamsTable."
  569. ::= { snmpTlstmCertificateMapping 4 }
  570. snmpTlstmParamsTableLastChanged OBJECT-TYPE
  571. SYNTAX TimeStamp
  572. MAX-ACCESS read-only
  573. STATUS current
  574. DESCRIPTION
  575. "The value of sysUpTime.0 when the snmpTlstmParamsTable
  576. was last modified through any means, or 0 if it has not been
  577. modified since the command responder was started."
  578. ::= { snmpTlstmCertificateMapping 5 }
  579. snmpTlstmParamsTable OBJECT-TYPE
  580. SYNTAX SEQUENCE OF SnmpTlstmParamsEntry
  581. MAX-ACCESS not-accessible
  582. STATUS current
  583. DESCRIPTION
  584. "This table is used by a (D)TLS client when a (D)TLS
  585. connection is being set up using an entry in the
  586. SNMP-TARGET-MIB. It extends the SNMP-TARGET-MIB's
  587. snmpTargetParamsTable with a fingerprint of a certificate to
  588. use when establishing such a (D)TLS connection."
  589. ::= { snmpTlstmCertificateMapping 6 }
  590. snmpTlstmParamsEntry OBJECT-TYPE
  591. SYNTAX SnmpTlstmParamsEntry
  592. MAX-ACCESS not-accessible
  593. STATUS current
  594. DESCRIPTION
  595. "A conceptual row containing a fingerprint hash of a locally
  596. held certificate for a given snmpTargetParamsEntry. The
  597. values in this row should be ignored if the connection that
  598. needs to be established, as indicated by the SNMP-TARGET-MIB
  599. infrastructure, is not a certificate and (D)TLS based
  600. connection. The connection SHOULD NOT be established if the
  601. certificate fingerprint stored in this entry does not point to
  602. a valid locally held certificate or if it points to an
  603. unusable certificate (such as might happen when the
  604. certificate's expiration date has been reached)."
  605. INDEX { IMPLIED snmpTargetParamsName }
  606. ::= { snmpTlstmParamsTable 1 }
  607. SnmpTlstmParamsEntry ::= SEQUENCE {
  608. snmpTlstmParamsClientFingerprint SnmpTLSFingerprint,
  609. snmpTlstmParamsStorageType StorageType,
  610. snmpTlstmParamsRowStatus RowStatus
  611. }
  612. snmpTlstmParamsClientFingerprint OBJECT-TYPE
  613. SYNTAX SnmpTLSFingerprint
  614. MAX-ACCESS read-create
  615. STATUS current
  616. DESCRIPTION
  617. "This object stores the hash of the public portion of a
  618. locally held X.509 certificate. The X.509 certificate, its
  619. public key, and the corresponding private key will be used
  620. when initiating a (D)TLS connection as a (D)TLS client."
  621. ::= { snmpTlstmParamsEntry 1 }
  622. snmpTlstmParamsStorageType OBJECT-TYPE
  623. SYNTAX StorageType
  624. MAX-ACCESS read-create
  625. STATUS current
  626. DESCRIPTION
  627. "The storage type for this conceptual row. Conceptual rows
  628. having the value 'permanent' need not allow write-access to
  629. any columnar objects in the row."
  630. DEFVAL { nonVolatile }
  631. ::= { snmpTlstmParamsEntry 2 }
  632. snmpTlstmParamsRowStatus OBJECT-TYPE
  633. SYNTAX RowStatus
  634. MAX-ACCESS read-create
  635. STATUS current
  636. DESCRIPTION
  637. "The status of this conceptual row. This object may be used
  638. to create or remove rows from this table.
  639. To create a row in this table, an administrator must set this
  640. object to either createAndGo(4) or createAndWait(5).
  641. Until instances of all corresponding columns are appropriately
  642. configured, the value of the corresponding instance of the
  643. snmpTlstmParamsRowStatus column is notReady(3).
  644. In particular, a newly created row cannot be made active until
  645. the corresponding snmpTlstmParamsClientFingerprint column has
  646. been set.
  647. The snmpTlstmParamsClientFingerprint object may not be modified
  648. while the value of this object is active(1).
  649. An attempt to set these objects while the value of
  650. snmpTlstmParamsRowStatus is active(1) will result in
  651. an inconsistentValue error."
  652. ::= { snmpTlstmParamsEntry 3 }
  653. snmpTlstmAddrCount OBJECT-TYPE
  654. SYNTAX Gauge32
  655. MAX-ACCESS read-only
  656. STATUS current
  657. DESCRIPTION
  658. "A count of the number of entries in the snmpTlstmAddrTable."
  659. ::= { snmpTlstmCertificateMapping 7 }
  660. snmpTlstmAddrTableLastChanged OBJECT-TYPE
  661. SYNTAX TimeStamp
  662. MAX-ACCESS read-only
  663. STATUS current
  664. DESCRIPTION
  665. "The value of sysUpTime.0 when the snmpTlstmAddrTable
  666. was last modified through any means, or 0 if it has not been
  667. modified since the command responder was started."
  668. ::= { snmpTlstmCertificateMapping 8 }
  669. snmpTlstmAddrTable OBJECT-TYPE
  670. SYNTAX SEQUENCE OF SnmpTlstmAddrEntry
  671. MAX-ACCESS not-accessible
  672. STATUS current
  673. DESCRIPTION
  674. "This table is used by a (D)TLS client when a (D)TLS
  675. connection is being set up using an entry in the
  676. SNMP-TARGET-MIB. It extends the SNMP-TARGET-MIB's
  677. snmpTargetAddrTable so that the client can verify that the
  678. correct server has been reached. This verification can use
  679. either a certificate fingerprint, or an identity
  680. authenticated via certification path validation.
  681. If there is an active row in this table corresponding to the
  682. entry in the SNMP-TARGET-MIB that was used to establish the
  683. connection, and the row's snmpTlstmAddrServerFingerprint
  684. column has non-empty value, then the server's presented
  685. certificate is compared with the
  686. snmpTlstmAddrServerFingerprint value (and the
  687. snmpTlstmAddrServerIdentity column is ignored). If the
  688. fingerprint matches, the verification has succeeded. If the
  689. fingerprint does not match, then the connection MUST be
  690. closed.
  691. If the server's presented certificate has passed
  692. certification path validation [RFC5280] to a configured
  693. trust anchor, and an active row exists with a zero-length
  694. snmpTlstmAddrServerFingerprint value, then the
  695. snmpTlstmAddrServerIdentity column contains the expected
  696. host name. This expected host name is then compared against
  697. the server's certificate as follows:
  698. - Implementations MUST support matching the expected host
  699. name against a dNSName in the subjectAltName extension
  700. field and MAY support checking the name against the
  701. CommonName portion of the subject distinguished name.
  702. - The '*' (ASCII 0x2a) wildcard character is allowed in the
  703. dNSName of the subjectAltName extension (and in common
  704. name, if used to store the host name), but only as the
  705. left-most (least significant) DNS label in that value.
  706. This wildcard matches any left-most DNS label in the
  707. server name. That is, the subject *.example.com matches
  708. the server names a.example.com and b.example.com, but does
  709. not match example.com or a.b.example.com. Implementations
  710. MUST support wildcards in certificates as specified above,
  711. but MAY provide a configuration option to disable them.
  712. - If the locally configured name is an internationalized
  713. domain name, conforming implementations MUST convert it to
  714. the ASCII Compatible Encoding (ACE) format for performing
  715. comparisons, as specified in Section 7 of [RFC5280].
  716. If the expected host name fails these conditions then the
  717. connection MUST be closed.
  718. If there is no row in this table corresponding to the entry
  719. in the SNMP-TARGET-MIB and the server can be authorized by
  720. another, implementation-dependent means, then the connection
  721. MAY still proceed."
  722. ::= { snmpTlstmCertificateMapping 9 }
  723. snmpTlstmAddrEntry OBJECT-TYPE
  724. SYNTAX SnmpTlstmAddrEntry
  725. MAX-ACCESS not-accessible
  726. STATUS current
  727. DESCRIPTION
  728. "A conceptual row containing a copy of a certificate's
  729. fingerprint for a given snmpTargetAddrEntry. The values in
  730. this row should be ignored if the connection that needs to be
  731. established, as indicated by the SNMP-TARGET-MIB
  732. infrastructure, is not a (D)TLS based connection. If an
  733. snmpTlstmAddrEntry exists for a given snmpTargetAddrEntry, then
  734. the presented server certificate MUST match or the connection
  735. MUST NOT be established. If a row in this table does not
  736. exist to match an snmpTargetAddrEntry row, then the connection
  737. SHOULD still proceed if some other certificate validation path
  738. algorithm (e.g., RFC 5280) can be used."
  739. INDEX { IMPLIED snmpTargetAddrName }
  740. ::= { snmpTlstmAddrTable 1 }
  741. SnmpTlstmAddrEntry ::= SEQUENCE {
  742. snmpTlstmAddrServerFingerprint SnmpTLSFingerprint,
  743. snmpTlstmAddrServerIdentity SnmpAdminString,
  744. snmpTlstmAddrStorageType StorageType,
  745. snmpTlstmAddrRowStatus RowStatus
  746. }
  747. snmpTlstmAddrServerFingerprint OBJECT-TYPE
  748. SYNTAX SnmpTLSFingerprint
  749. MAX-ACCESS read-create
  750. STATUS current
  751. DESCRIPTION
  752. "A cryptographic hash of a public X.509 certificate. This
  753. object should store the hash of the public X.509 certificate
  754. that the remote server should present during the (D)TLS
  755. connection setup. The fingerprint of the presented
  756. certificate and this hash value MUST match exactly or the
  757. connection MUST NOT be established."
  758. DEFVAL { "" }
  759. ::= { snmpTlstmAddrEntry 1 }
  760. snmpTlstmAddrServerIdentity OBJECT-TYPE
  761. SYNTAX SnmpAdminString
  762. MAX-ACCESS read-create
  763. STATUS current
  764. DESCRIPTION
  765. "The reference identity to check against the identity
  766. presented by the remote system."
  767. DEFVAL { "" }
  768. ::= { snmpTlstmAddrEntry 2 }
  769. snmpTlstmAddrStorageType OBJECT-TYPE
  770. SYNTAX StorageType
  771. MAX-ACCESS read-create
  772. STATUS current
  773. DESCRIPTION
  774. "The storage type for this conceptual row. Conceptual rows
  775. having the value 'permanent' need not allow write-access to
  776. any columnar objects in the row."
  777. DEFVAL { nonVolatile }
  778. ::= { snmpTlstmAddrEntry 3 }
  779. snmpTlstmAddrRowStatus OBJECT-TYPE
  780. SYNTAX RowStatus
  781. MAX-ACCESS read-create
  782. STATUS current
  783. DESCRIPTION
  784. "The status of this conceptual row. This object may be used
  785. to create or remove rows from this table.
  786. To create a row in this table, an administrator must set this
  787. object to either createAndGo(4) or createAndWait(5).
  788. Until instances of all corresponding columns are
  789. appropriately configured, the value of the
  790. corresponding instance of the snmpTlstmAddrRowStatus
  791. column is notReady(3).
  792. In particular, a newly created row cannot be made active until
  793. the corresponding snmpTlstmAddrServerFingerprint column has been
  794. set.
  795. Rows MUST NOT be active if the snmpTlstmAddrServerFingerprint
  796. column is blank and the snmpTlstmAddrServerIdentity is set to
  797. '*' since this would insecurely accept any presented
  798. certificate.
  799. The snmpTlstmAddrServerFingerprint object may not be modified
  800. while the value of this object is active(1).
  801. An attempt to set these objects while the value of
  802. snmpTlstmAddrRowStatus is active(1) will result in
  803. an inconsistentValue error."
  804. ::= { snmpTlstmAddrEntry 4 }
  805. -- ************************************************
  806. -- snmpTlstmNotifications - Notifications Information
  807. -- ************************************************
  808. snmpTlstmServerCertificateUnknown NOTIFICATION-TYPE
  809. OBJECTS { snmpTlstmSessionUnknownServerCertificate }
  810. STATUS current
  811. DESCRIPTION
  812. "Notification that the server certificate presented by an SNMP
  813. over (D)TLS server was invalid because no configured
  814. fingerprint or CA was acceptable to validate it. This may be
  815. because there was no entry in the snmpTlstmAddrTable or
  816. because no path could be found to known Certification
  817. Authority.
  818. To avoid notification loops, this notification MUST NOT be
  819. sent to servers that themselves have triggered the
  820. notification."
  821. ::= { snmpTlstmNotifications 1 }
  822. snmpTlstmServerInvalidCertificate NOTIFICATION-TYPE
  823. OBJECTS { snmpTlstmAddrServerFingerprint,
  824. snmpTlstmSessionInvalidServerCertificates}
  825. STATUS current
  826. DESCRIPTION
  827. "Notification that the server certificate presented by an SNMP
  828. over (D)TLS server could not be validated even if the
  829. fingerprint or expected validation path was known. That is, a
  830. cryptographic validation error occurred during certificate
  831. validation processing.
  832. To avoid notification loops, this notification MUST NOT be
  833. sent to servers that themselves have triggered the
  834. notification."
  835. ::= { snmpTlstmNotifications 2 }
  836. -- ************************************************
  837. -- snmpTlstmCompliances - Conformance Information
  838. -- ************************************************
  839. snmpTlstmCompliances OBJECT IDENTIFIER ::= { snmpTlstmConformance 1 }
  840. snmpTlstmGroups OBJECT IDENTIFIER ::= { snmpTlstmConformance 2 }
  841. -- ************************************************
  842. -- Compliance statements
  843. -- ************************************************
  844. snmpTlstmCompliance MODULE-COMPLIANCE
  845. STATUS current
  846. DESCRIPTION
  847. "The compliance statement for SNMP engines that support the
  848. SNMP-TLS-TM-MIB"
  849. MODULE
  850. MANDATORY-GROUPS { snmpTlstmStatsGroup,
  851. snmpTlstmIncomingGroup,
  852. snmpTlstmOutgoingGroup,
  853. snmpTlstmNotificationGroup }
  854. ::= { snmpTlstmCompliances 1 }
  855. -- ************************************************
  856. -- Units of conformance
  857. -- ************************************************
  858. snmpTlstmStatsGroup OBJECT-GROUP
  859. OBJECTS {
  860. snmpTlstmSessionOpens,
  861. snmpTlstmSessionClientCloses,
  862. snmpTlstmSessionOpenErrors,
  863. snmpTlstmSessionAccepts,
  864. snmpTlstmSessionServerCloses,
  865. snmpTlstmSessionNoSessions,
  866. snmpTlstmSessionInvalidClientCertificates,
  867. snmpTlstmSessionUnknownServerCertificate,
  868. snmpTlstmSessionInvalidServerCertificates,
  869. snmpTlstmSessionInvalidCaches
  870. }
  871. STATUS current
  872. DESCRIPTION
  873. "A collection of objects for maintaining
  874. statistical information of an SNMP engine that
  875. implements the SNMP TLS Transport Model."
  876. ::= { snmpTlstmGroups 1 }
  877. snmpTlstmIncomingGroup OBJECT-GROUP
  878. OBJECTS {
  879. snmpTlstmCertToTSNCount,
  880. snmpTlstmCertToTSNTableLastChanged,
  881. snmpTlstmCertToTSNFingerprint,
  882. snmpTlstmCertToTSNMapType,
  883. snmpTlstmCertToTSNData,
  884. snmpTlstmCertToTSNStorageType,
  885. snmpTlstmCertToTSNRowStatus
  886. }
  887. STATUS current
  888. DESCRIPTION
  889. "A collection of objects for maintaining
  890. incoming connection certificate mappings to
  891. tmSecurityNames of an SNMP engine that implements the
  892. SNMP TLS Transport Model."
  893. ::= { snmpTlstmGroups 2 }
  894. snmpTlstmOutgoingGroup OBJECT-GROUP
  895. OBJECTS {
  896. snmpTlstmParamsCount,
  897. snmpTlstmParamsTableLastChanged,
  898. snmpTlstmParamsClientFingerprint,
  899. snmpTlstmParamsStorageType,
  900. snmpTlstmParamsRowStatus,
  901. snmpTlstmAddrCount,
  902. snmpTlstmAddrTableLastChanged,
  903. snmpTlstmAddrServerFingerprint,
  904. snmpTlstmAddrServerIdentity,
  905. snmpTlstmAddrStorageType,
  906. snmpTlstmAddrRowStatus
  907. }
  908. STATUS current
  909. DESCRIPTION
  910. "A collection of objects for maintaining
  911. outgoing connection certificates to use when opening
  912. connections as a result of SNMP-TARGET-MIB settings."
  913. ::= { snmpTlstmGroups 3 }
  914. snmpTlstmNotificationGroup NOTIFICATION-GROUP
  915. NOTIFICATIONS {
  916. snmpTlstmServerCertificateUnknown,
  917. snmpTlstmServerInvalidCertificate
  918. }
  919. STATUS current
  920. DESCRIPTION
  921. "Notifications"
  922. ::= { snmpTlstmGroups 4 }
  923. END