Attributes | Values |
---|
rdf:type
| |
rdfs:label
| |
http://yang.eurecom.fr/yin#description
| - This list defines how certificates are mapped to names.
The name is derived by considering each cert-to-name
list entry in order. The cert-to-name entry's fingerprint
determines whether the list entry is a match:
1) If the cert-to-name list entry's fingerprint value
matches that of the presented certificate, then consider
the list entry a successful match.
2) If the cert-to-name list entry's fingerprint value
matches that of a locally held copy of a trusted CA
certificate, and that CA certificate was part of the CA
certificate chain to the presented certificate, then
consider the list entry a successful match.
Once a matching cert-to-name list entry has been found, the
map-type is used to determine how the name associated with
the certificate should be determined. See the map-type
leaf's description for details on determining the name value.
If it is impossible to determine a name from the cert-to-name
list entry's data combined with the data presented in the
certificate, then additional cert-to-name list entries MUST
be searched to look for another potential match.
Security administrators are encouraged to make use of
certificates with subjectAltName fields that can be mapped to
names so that a single root CA certificate can allow all
child certificates' subjectAltName fields to map directly to
a name via a 1:1 transformation.
|
http://yang.eurecom.fr/yin#prefix
| |
http://yang.eurecom.fr/yin#reference
| - RFC 6353: Transport Layer Security (TLS) Transport Model
for the Simple Network Management Protocol (SNMP).
SNMP-TLS-TM-MIB.snmpTlstmCertToTSNEntry
|
http://yang.eurecom.fr/yin#hasLeaf
| |
http://yang.eurecom.fr/yin#key
| |
http://yang.eurecom.fr/yin#config
| |
http://yang.eurecom.fr/yin#fullPath
| - /snmp:snmp?container/snmp:tlstm?container/snmp:cert-to-name?list
|
is http://yang.eurecom.fr/yin#hasList
of | |