The MIB module for managing an IEEE 802.1AR DevID (Secure Device Identifier) Module. A DevID comprises: a DevID secret (a private key) stored confidentially by the DevID module and accessible only through operations provided by the module; a DevID certificate containing the corresponding public key and a subject name that identifies the device; and a (possibly null) certificate chain. Use of the DevID module signing operations allows the device to prove possession of the DevID secret, and thus assert its identity in authentication protocols. An initial IDevID provided by the device supplier can be used directly or can be used to provision one or more locally significant LDevIDs that reflect authorization decisions by the local network administrator with certificate fields that record those decisions. An SNMP agent can manage a network element comprising one or many devices. They can include component (such as individual line cards in a chassis) or aggregate devices (such as the chassis and its current complement of cards). In each case a DevID module binds DevIDs secrets and certificates to the device whose identity they can be used to assert: they remain attached to a component device if it is
removed from the network element, and are not retained by the SNMP
agent. The entPhysicalIndex defined by the ENTITY-MIB identifies each device managed by the agent and is used to index tables of managed objects for each device with a DevID module, so ENTITY-MIB objects are correlated with and can supplement DevID information cryptographically bound to the device. The initial version of this ieee8021DevIDMIB used the object name prefix 'devID' rather than 'ieee8021DevI' as recommended by RFC 4181. The 'devID' prefix has been retained for backwards compatibility and internal consistency.
The total number of DevID public keys installed in the module. Obsolete: the number of currently installed keys is the number of DevIDCertEntry's with the module's entPhysicalIndex and distinct devIDCertPublicKeyInfoFprint values, the maximum number can be an implementation dependent function of the keys' signature suites and the storage occupied by certificates and certificate chains. Reference: IEEE 802.1AR-2009 6.4, and 6.3.2
devIDCredentialCount
1.3.111.2.802.1.1.17.1.2.3
Unsigned32
This gives the total number of DevID credentials installed in the DevID module. Obsolete: Object is not indexed by entPhysicalIndex so is not a per module count if the agent is managing multiple devices. Changes as component devices are added or removed are not meaningful without other information. Per module counts can be obtained by interrogating the devIDCertTable. Reference: IEEE 802.1AR-2009 6.4, and 6.3.2
Table details
devIDPublicKeyTable
1.3.111.2.802.1.1.17.1.2.2
Index: entPhysicalIndex
A table containing the public key, the keys keyIndex, a value indicating if the key is enabled. This allows the administrator to determine the DevID keys installed in the DevID module. The maximum number of entries in this table is limited by the value of devIDPublicKeyCount. Obsolete: the public keys that have been installed and may be used can be obtained from the subjectPublicKeyInfo field in each of the DevIDCertEntry's devIDCert object. Reference: IEEE 802.1AR-2009 6.4, and 6.3.2
PhysicalIndexAn arbitrary value that uniquely identifies the physical entity. The value should be a small positive integer. Index values for different physical entities are not necessarily contiguous. (1..2147483647) · Integer32 · hint d
The index for this entry.
devIDPublicKeyIndex
1.3.111.2.802.1.1.17.1.2.2.1.1
Unsigned32
All keys are indexed internally with this object. The value of this object is within 0..devIDPublicKeyCount. This is the keyIndex and operations on keys will use the keyIndex to address a specific key. The IDevID key shall only be at index 0. Any error retrieving a key will be displayed in devIDPublicKeyErrStatus. Obsolete: the potential indexes are close packed forcing index reuse not under the agents control so reading the index from the devIDCredentialTable and then using it with this object may not retrieve the intended key. Reference: IEEE 802.1AR-2009 6.4, and 6.3.2
devIDPublicKeyEnabled
1.3.111.2.802.1.1.17.1.2.2.1.2
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
The enable/disable state of this public key. This setting persists across restarts. Obsolete with table. Reference: IEEE 802.1AR-2009 6.4, and 6.3.2
devIDPublicKeyAlgorithm
1.3.111.2.802.1.1.17.1.2.2.1.3
DevIDAlgorithmIdentifier1 = rsaEncryption2 = idecPublicKeyThe algorithm type for the public key. · Integer32
The DevID PublicKey Algorithm field shall indicate the public key algorithm identifier. This object identifies the public key algorithm as either rsaEncryption or idecPublicKey. Obsolete along with table. The AlgorithmIdentifier is not necessarily a complete description of the signature suite (parameters in subjectPublicKeyInfo may also be required), full information is in the devIDCert in the devIDCertTable using X.509 OIDs so avoiding generating new OIDs for this MIB and removing the need for future MIB updates as new signature suites are added. Reference: IEEE 802.1AR-2009 6.4, 6.3.2 and 7.2.9
devIDPublicKeyPubkeySHA1Hash
1.3.111.2.802.1.1.17.1.2.2.1.4
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The SHA1 Hash of this DevID public key. Obsolete with table. DevIDFingerprint used in new table objects to provided allow hash flexibility without MIB update. Reference: IEEE 802.1AR-2009 6.4, 6.3.2 and 7.2.9
devIDPublicKeyErrStatus
1.3.111.2.802.1.1.17.1.2.2.1.5
DevIDErrorStatus1 = none2 = internalErrorThe error state of a DevID operation. · Integer32
Displays the status of an operation on the public key. The default value is none which means no error, indicating a successful operation. Obsolete: DevID module service interface operations are not visible in this MIB so this object provides no clue as to what has failed and does not specify whether it is cleared by subsequent successful operations. If keys or certs are unusable they should not be visible to SNMP or appear not enabled. In both cases this read-only MIB cannot diagnose or repair. SNMP operations already have their own error codes. Reference: IEEE 802.1AR-2009 6.4, and 6.3.2
devIDCredentialTable
1.3.111.2.802.1.1.17.1.2.4
Index: devIDCredentialIndex
A table of current DevID credentials, where for each certificate the following are indicated: sha1 hash of the certificate, section7 defined fields of cert serial number, issuer, subject, HardwareModuleName, and public key. Obsolete: the ASN.1 encoding of a certificate is already defined elsewhere, there is no need to require a device to decode the certificate into a different ASN.1 structure, and picking particular field might omit problematic extensions in particular certificates. Reference: IEEE 802.1AR-2009 6.4, and 6.3.3
devIDCredentialIndex
1.3.111.2.802.1.1.17.1.2.4.1.1
Unsigned32
All credentials are indexed internally with this
object. The value of this object is in [0..devIDCredentialCount].
Operations on credentials will use the credentialIndex to address a specific credential. The IDevID credential shall only be at index 0. Additional operations on credentials use the credentialIndex to address a specific credential. Obsolete: The SNP agent does not control or monitor individual DevID service operations, an SNMP agent can manage a system that comprises multiple devices identified by the ENTITY-MIB and more than one of those devices can have a DevID module with an IDevID. Reference: IEEE 802.1AR-2009 6.4, and 6.3.2
devIDCredentialEnabled
1.3.111.2.802.1.1.17.1.2.4.1.2
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
The enable/disable state of this credential. This setting persists across restarts. Obsolete with table. Reference: IEEE 802.1AR-2009 6.3.6
devIDCredentialSHA1Hash
1.3.111.2.802.1.1.17.1.2.4.1.3
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The SHA1 Hash of this DevID credential. Obsolete with table. Reference: IEEE 802.1AR 7.2.2
devIDCredentialSerialNumber
1.3.111.2.802.1.1.17.1.2.4.1.4
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..20) · OCTET STRING · hint 255t
The serial number of the credential. Obsolete with table. Reference: IEEE 802.1AR-2009 7.2.2
devIDCredentialIssuer
1.3.111.2.802.1.1.17.1.2.4.1.5
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The issuer field of the credential. Obsolete with table. Reference: IEEE 802.1AR-2009 7.2.4
devIDCredentialSubject
1.3.111.2.802.1.1.17.1.2.4.1.6
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The subject field of the credential. Obsolete with table. Reference: IEEE 802.1AR-2009 7.2.8
devIDCredentialSubjectAltName
1.3.111.2.802.1.1.17.1.2.4.1.7
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The subjectaltname field of the credential. Obsolete with table. Reference: IEEE 802.1AR-2009 7.2.8
devIDCredentialEntityIndex
1.3.111.2.802.1.1.17.1.2.4.1.8
PhysicalIndexAn arbitrary value that uniquely identifies the physical entity. The value should be a small positive integer. Index values for different physical entities are not necessarily contiguous. (1..2147483647) · Integer32 · hint d
This refers to the entPhysicalIndex in entPhysicalTable to identify the associated physical entity. Obsolete with table. Reference: IEEE 802.1AR-2009 6.4
devIDCredentialPubkeyIndex
1.3.111.2.802.1.1.17.1.2.4.1.9
Unsigned32
Has the appropriate devIDPublicKeyIndex value from devIDPublicKeyTable to identify the public key information. Obsolete with table. Reference: IEEE 802.1AR-2009 7.2.9
devIDCredentialErrStatus
1.3.111.2.802.1.1.17.1.2.4.1.10
DevIDErrorStatus1 = none2 = internalErrorThe error state of a DevID operation. · Integer32
The displays the status of an operation on the credential. The default value is none which means no error, indicating a successful operation. Obsolete with table. Reference: IEEE 802.1AR-2009 6.4, and 6.3.2
devIDStatisticsTable
1.3.111.2.802.1.1.17.1.2.5
Index: entPhysicalIndex
Counts of selected operations for each DevID module. Reference: IEEE 802.1AR 7.3.
PhysicalIndexAn arbitrary value that uniquely identifies the physical entity. The value should be a small positive integer. Index values for different physical entities are not necessarily contiguous. (1..2147483647) · Integer32 · hint d
The index for this entry.
devIDStatisticKeyGenerationCount
1.3.111.2.802.1.1.17.1.2.5.1.1
Counter32
The number of LDevID key pairs generated by the module. Discontinuities at system restart and counter rollover. Reference: IEEE 802.1AR 7.2.8, 7.3.
devIDStatisticKeyInsertionCount
1.3.111.2.802.1.1.17.1.2.5.1.2
Counter32
The number of LDevID key pairs inserted into the module. Discontinuities occur at system restart and counter rollover. Reference: IEEE 802.1AR 7.2.9, 7.3.
devIDStatisticKeyDeletionCount
1.3.111.2.802.1.1.17.1.2.5.1.3
Counter32
The number of LDevID key pairs deleted by the module. Discontinuities occur at system restart and counter rollover. Reference: IEEE 802.1AR 7.2.10, 7.3.
devIDStatisticCSRGenerationCount
1.3.111.2.802.1.1.17.1.2.5.1.4
Counter32
The number of Certificate Signing Requests (CSR, RFC2986) generated by the module. Discontinuities occur at system restart and counter rollover. Deprecated: the module does not necessarily have all the information to generate a meaningful CSR, and key and certificate insertion is not tied to prior CSR generation. If required the signing operation can generate a CSR though this is not required for LDevID insertion. Reference: IEEE 802.1AR-2009 6.4, and 6.3.11
devIDStatisticCredentialInsertionCount
1.3.111.2.802.1.1.17.1.2.5.1.5
Counter32
The number of LDevID credential insertions. Discontinuities occur at system restart and counter rollover. Reference: IEEE 802.1AR-2009 6.4, and 6.3.12.
devIDStatisticCredentialDeletionCount
1.3.111.2.802.1.1.17.1.2.5.1.6
Counter32
The number of LDevID credential deletions. Discontinuities occur at system restart and counter rollover. Reference: IEEE 802.1AR-2009 6.4, and 6.3.14.
devIDStatisticCertInsertionCount
1.3.111.2.802.1.1.17.1.2.5.1.7
Counter32
The number of LDevID certificate insertions. Discontinuities occur at system restart and counter rollover. Reference: IEEE 802.1AR 7.2.11, 7.3.
devIDStatisticCertDeletionCount
1.3.111.2.802.1.1.17.1.2.5.1.8
Counter32
This number of LDevID certificate deletions. Discontinuities occur at system restart and counter rollover. Reference: IEEE 802.1AR 7.2.13.
devIDModuleTable
1.3.111.2.802.1.1.17.1.2.6
Index: entPhysicalIndex
A table of DevID module capabilities, which can differ for devices managed by the same SNMP agent. Reference: IEEE 802.1AR 7.3, 10.2, 10.3
PhysicalIndexAn arbitrary value that uniquely identifies the physical entity. The value should be a small positive integer. Index values for different physical entities are not necessarily contiguous. (1..2147483647) · Integer32 · hint d
The index for this entry.
devIDModuleSupportsLDevIDs
1.3.111.2.802.1.1.17.1.2.6.1.1
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
True if the module supports the mandatory operations for LDevIDs. Reference: IEEE 802.1AR 7.2(k)-(n).
devIDModuleGeneratesLDevIDKeys
1.3.111.2.802.1.1.17.1.2.6.1.2
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
True if the module supports LDevID key generation. Reference: IEEE 802.1AR 7.2(h), 7.2(j), 7.2.8, 7.2.10.
devIDModuleInsertsLDevIDKeys
1.3.111.2.802.1.1.17.1.2.6.1.3
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
True if the module supports LDevID key insertion. Reference: IEEE 802.1AR 7.2(i), 7.2(j), 7.2.9, 7.2.10, 7.3.
devIDCertTable
1.3.111.2.802.1.1.17.1.2.7
Index: entPhysicalIndex · devIDCertFingerprint
A table of DevID certificates, indexed by entPhysicalIndex (identifying the DevID module to which the certificate belongs) and the certificate's fingerprint. Reference: IEEE 802.1AR Clause 6, 6.2, 7.2.2, 7.2.3, 7.2.6, 7.2.7, 7.2.11, 7.2.13, 7.3.
PhysicalIndexAn arbitrary value that uniquely identifies the physical entity. The value should be a small positive integer. Index values for different physical entities are not necessarily contiguous. (1..2147483647) · Integer32 · hint d
The index for this entry.
devIDCertFingerprint
1.3.111.2.802.1.1.17.1.2.7.1.1
DevIDFingerprintA Named Information identifier (RFC 6920) comprising a single octet (an IANA (iana.org) Named Information Hash Algorithm Registry value) followed by the result of applying that identified
(possibly truncated) hash function to the arbitrary long octet
string to be fingerprinted. The fingerprint size (including the initial identifier) is limited to 49 octets to meet the SNMP oid size constraints when used as an INDEX while allowing the use of sha3-384, but sha-256-32 or sha-256-64 (5 or 9 octets total) is recommended with checking of full, not fingerprint, values in sensitive applications. This TEXTUAL-CONVENTION allows a zero-length value where the fingerprint value is optional. MIB definitions or implementations may refuse to accept a zero-length value. SIZE (0..49) · OCTET STRING · hint 1x:1x
A fingerprint of the DevID certificate, identifying the fingerprinting hash. Reference: IEEE 802.1AR 10.3
devIDCertPublicKeyInfoFprint
1.3.111.2.802.1.1.17.1.2.7.1.2
DevIDFingerprintA Named Information identifier (RFC 6920) comprising a single octet (an IANA (iana.org) Named Information Hash Algorithm Registry value) followed by the result of applying that identified
(possibly truncated) hash function to the arbitrary long octet
string to be fingerprinted. The fingerprint size (including the initial identifier) is limited to 49 octets to meet the SNMP oid size constraints when used as an INDEX while allowing the use of sha3-384, but sha-256-32 or sha-256-64 (5 or 9 octets total) is recommended with checking of full, not fingerprint, values in sensitive applications. This TEXTUAL-CONVENTION allows a zero-length value where the fingerprint value is optional. MIB definitions or implementations may refuse to accept a zero-length value. SIZE (0..49) · OCTET STRING · hint 1x:1x
A fingerprint of the DevID certificate's subjectPublicKeyInfo field, identifying the fingerprinting hash. Reference: IEEE 802.1AR 10.3
devIDCertIDevID
1.3.111.2.802.1.1.17.1.2.7.1.3
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
True if this is an IDevID Certificate. Reference: IEEE 802.1AR Clause 6, 6.2, 7.3.
devIDCertKeyEnabled
1.3.111.2.802.1.1.17.1.2.7.1.4
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
True if use of the DevID Secret for this certificate is enabled, allowing its use. Reference: IEEE 802.1AR 7.2.7, 7.3
devIDCertEnabled
1.3.111.2.802.1.1.17.1.2.7.1.5
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
True if the certificate can be used. Reference: IEEE 802.1AR 7.2.6
A table of DevID intermediate certificates, indexed by entPhysicalIndex (identifying the DevID module), devIDCertFingerprint (identifying the DevID certificate), and devIDChainCertIndex (identifying the certificate's position in the certificate chain, upwards from the DevID certificate). Reference: IEEE 802.1AR 10.3, 6.3, 7.2.3.
PhysicalIndexAn arbitrary value that uniquely identifies the physical entity. The value should be a small positive integer. Index values for different physical entities are not necessarily contiguous. (1..2147483647) · Integer32 · hint d
The index for this entry.
devIDChainCertIndex
1.3.111.2.802.1.1.17.1.2.8.1.1
Unsigned32
The position of this intermediate certificate in the certificate chain. Reference: IEEE 802.1AR 10.3.
devIDChainCertFingerprint
1.3.111.2.802.1.1.17.1.2.8.1.2
DevIDFingerprintA Named Information identifier (RFC 6920) comprising a single octet (an IANA (iana.org) Named Information Hash Algorithm Registry value) followed by the result of applying that identified
(possibly truncated) hash function to the arbitrary long octet
string to be fingerprinted. The fingerprint size (including the initial identifier) is limited to 49 octets to meet the SNMP oid size constraints when used as an INDEX while allowing the use of sha3-384, but sha-256-32 or sha-256-64 (5 or 9 octets total) is recommended with checking of full, not fingerprint, values in sensitive applications. This TEXTUAL-CONVENTION allows a zero-length value where the fingerprint value is optional. MIB definitions or implementations may refuse to accept a zero-length value. SIZE (0..49) · OCTET STRING · hint 1x:1x
A fingerprint of the intermediate certificate, identifying the fingerprinting hash. Reference: IEEE 802.1AR 10.3.
devIDChainCert
1.3.111.2.802.1.1.17.1.2.8.1.3
OCTET STRING
The X.509 intermediate certificate in a certificate chain. Reference: IEEE 802.1AR 6.3, 7.3, Clause 8.