CISCO-FIREPOWER-PKI-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-FIREPOWER-PKI-MIB

Organization: Cisco Systems Inc.

Last Updated: 2022-08-25

Category: Cisco Devices, Hardware and Environment

Description: Provides management objects for PKI certificate and key pair management on Cisco UCS/Firepower management platforms.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-FIREPOWER-PKI-MIB?

CISCO-FIREPOWER-PKI-MIB is part of the Cisco UCS/Firepower model-based MIB family covering PKI certificate and key-pair management used to secure the platform's management plane (e.g. HTTPS/TLS access to the management GUI/API). It exposes certificate signing request (CSR) objects capturing the identity fields submitted for a certificate, such as country, DNS name, email, and IPv4/IPv6 addresses. This is a security/configuration-status MIB, useful for monitoring the state and content of in-flight certificate requests and detecting problems such as an expired or improperly formed request that could leave the management interface without valid TLS. As with sibling Firepower MIBs, it follows the shared Dn/Rn/InstanceId managed-object model of Cisco's UCS Manager information model rather than an external standards dependency, though the certificate fields themselves reflect standard X.509 CSR conventions. It is deployed on Cisco UCS/Firepower management platforms where administrators manage TLS certificates for secure management access. Network engineers evaluating or troubleshooting this functionality can download the CISCO-FIREPOWER-PKI-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-FIREPOWER-PKI-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco UCS/Firepower management platforms

Monitoring Examples

An admin can poll cfprPkiCertReqTable/cfprPkiCertReqEntry to inspect the cfprPkiCertReqCountry, cfprPkiCertReqDns, and cfprPkiCertReqIp/cfprPkiCertReqIpv6 fields of a pending certificate signing request, verifying the request contains the correct hostname and IP addresses before it is submitted to a certificate authority, catching a misconfigured CSR before it causes a certificate/hostname mismatch later.

What Can Be Monitored

  • certificate request identity fields (country, DNS, email, IP)
  • certificate request state
  • key pair association
Imported Objects

From CISCO-FIREPOWER-MIB

CfprManagedObjectDn
CfprManagedObjectId
ciscoFirepowerMIBObjectsOBJECT-IDENTITY

From CISCO-FIREPOWER-TC-MIB

CfprAaaConfigState
CfprAaaFqdnEnforceType
CfprConditionRemoteInvRslt
CfprFsmCompletion
CfprFsmFlags
CfprFsmFsmStageStatus
CfprPkiCertRevokeMethod
CfprPkiCertStatus
CfprPkiEc
CfprPkiEpFsmCurrentFsm
CfprPkiEpFsmStageName
CfprPkiEpFsmTaskItem
CfprPkiImportActivity
CfprPkiKeyringState
CfprPkiModulus
CfprPkiTpAutoImportImportControlStatus
CfprPkiTransferState
CfprPkiTransport
CfprPkiTransportNoLocal
CfprPkiType
CfprPolicyPolicyOwner

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

CiscoAlarmSeverity
CiscoInetAddressMask
CiscoNetworkAddress
TimeIntervalSec
Unsigned64

From INET-ADDRESS-MIB

InetAddressIPv4
InetAddressIPv6

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-SMI

Counter32
Counter64
Gauge32
MODULE-IDENTITY
OBJECT-TYPE
TimeTicks
Unsigned32

From SNMPv2-TC

DateAndTime
DisplayString
MacAddress
RowPointer
TEXTUAL-CONVENTION
TimeInterval
TimeStamp
TruthValue
OIDs

RFC description

Manages public key infrastructure certificates and key management on Cisco Firepower security appliances.

Start monitoring Cisco UCS/Firepower management platforms with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-FIREPOWER-PKI-MIB