Network\CIM_ESPTransform.mof.mof (HTML version)

Return to index
CIM_ESPTransform Superclass: CIM_SATransform
ESPTransform defines the parameters used for a phase 2 ESP (Encapsulating Security Protocol) Security Association.
Qualifiers:Version ( "2.8.0" ) MappingStrings { "IPSP Model.IETF|ESPTransform" }
Parameters (local in grey)
MappingStrings { "IPSP " "Model.IETF|ESPTransform.ReplayPreventionWindowSize" }
Units ( "Bits" )
uint32 ReplayPreventionWindowSize ;
ReplayPreventionWindowsSize specifies, in bits, the length of the sliding window used by the replay prevention mechanism. The value of this property is meaningless if UseReplayPrevention is false. The window size MUST be a power of 2.
ModelCorrespondence { "CIM_ESPTransform.IntegrityTransformId" }
string OtherIntegrityTransformId ;
Description of the integrity algorithm when the value 1 ('Other') is specified for the property, IntegrityTransformId.
Values { "Other" , "None" , "DES_IV64" , "DES" , "3DES" , "RC5" , "IDEA" , "CAST" , "Blowfish" , "3-IDEA" , "DES_IV32" , "RC4" }
ModelCorrespondence { "CIM_ESPTransform.OtherCipherTransformId" }
ValueMap { "1" , "2" , "3" , "4" , "5" , "6" , "7" , "8" , "9" , "10" , "11" , "12" }
MappingStrings { "IPSP " "Model.IETF|ESPTransform.CipherTransformId" , "RFC2407.IETF|Section 4.4.4" }
uint16 CipherTransformId ;
CipherTransformId is an enumeration that specifies the ESP encrypion algorithm to be used. The list of values is defined in RFC2407, Section 4.4.4, where the RFC's NULL value maps to 2-'None'. Note that the enumeration is different than the RFC list, since 'Other' is added to the enumeration.
ModelCorrespondence { "CIM_ESPTransform.CipherTransformId" }
string OtherCipherTransformId ;
Description of the encryption algorithm when the value 1 ('Other') is specified for the property, CipherTransformId.
Values { "Other" , "None" , "MD5" , "SHA-1" , "DES" , "KPDK" , "DMTF/IANA Reserved" , "Vendor Reserved" }
ModelCorrespondence { "CIM_ESPTransform.OtherIntegrityTransformId" }
ValueMap { "1" , "2" , "3" , "4" , "5" , "6" , "7..61439" , "61440..65535" }
MappingStrings { "IPSP " "Model.IETF|ESPTransform.IntegrityTransformId" , "RFC2407.IETF|Section 4.5" }
uint16 IntegrityTransformId ;
IntegrityTransformId is an enumeration that specifies the ESP integrity algorithm to be used. The list of values is generated from the enumeration defined in RFC2407, Section 4.5. Note that the enumeration is different than the RFC list, since the values of Other and None are taken into account. Also, note that 2 ('None') is used when ESP is negotiated without authentication.
MappingStrings { "IPSP Model.IETF|ESPTransform.CipherKeyLength" }
Units ( "Bits" )
uint16 CipherKeyLength ;
CipherKeyLength specifies, in bits, the key length for the encryption algorithm. For algorithms with fixed key lengths, this value is ignored.
MappingStrings { "IPSP " "Model.IETF|ESPTransform.UseReplayPrevention" }
boolean UseReplayPrevention ;
UseReplayPrevention causes the local peer to enable replay prevention detection. This can be accomplished by using a sequence number when sending a packet or checking the sequence number upon receipt of a packet.
MappingStrings { "IPSP Model.IETF|ESPTransform.CipherKeyRounds" }
uint16 CipherKeyRounds ;
CipherKeyRounds specifies the key rounds for the encryption algorithm. For algorithms with a fixed number of key rounds, this value is ignored. Currently, key rounds are NOT defined for any ESP encryption algorithms.
MappingStrings { "IPSP Model.IETF|SATransform.VendorID" }
string VendorID = "" ;
VendorID identifies vendor-defined transforms. If this field is empty (the default), then this is a standard transform.
Override ( "ElementName" )
MappingStrings { "IPSP Model.IETF|SATransform.CommonName" }
string ElementName ;
MappingStrings { "IPSP " "Model.IETF|SATransform.MaxLifetimeKilobytes" }
Units ( "KiloBytes" )
uint64 MaxLifetimeKilobytes = 0 ;
MaxLifetimeKilobytes specifies the maximum kilobyte lifetime for a Security Association. Different lifetimes are used, depending on the strength of the encryption algorithm. A value of 0, the default, indicates that no maximum should be defined. A non-zero value specifies the desired kilobyte lifetime.
MappingStrings { "IPSP " "Model.IETF|SATransform.MaxLifetimeSeconds" }
Units ( "Seconds" )
uint64 MaxLifetimeSeconds = 0 ;
MaxLifetimeSeconds specifies the maximum time that the Security Association should be considered valid after it has been created. A value of 0, the default, indicates that 8 hours should be used. A non-zero value indicates the maximum lifetime in seconds.
Key
string InstanceID ;
Within the scope of the instantiating Namespace, InstanceID opaquely and uniquely identifies an instance of this class. To ensure uniqueness within the NameSpace, the value of InstanceID should be constructed using the following 'preferred' algorithm:
<OrgID>:<LocalID>
Where <OrgID> and <LocalID> are separated by a colon (:), and where <OrgID> must include a copyrighted, trademarked, or otherwise unique name that is owned by the business entity that is creating or defining the InstanceID or that is a registered ID assigned to the business entity by a recognized global authority. (This requirement is similar to the <Schema Name>_<Class Name> structure of Schema class names.) In addition, to ensure uniqueness, <OrgID> must not contain a colon (:). When using this algorithm, the first colon to appear in InstanceID must appear between <OrgID> and <LocalID>.
<LocalID> is chosen by the business entity and should not be reused to identify different underlying (real-world) elements. If the above 'preferred' algorithm is not used, the defining entity must assure that the resulting InstanceID is not reused across any InstanceIDs produced by this or other providers for the NameSpace of this instance.
For DMTF-defined instances, the 'preferred' algorithm must be used with the <OrgID> set to CIM.
MaxLen ( 64 )
string Caption ;
The Caption property is a short textual description (one- line string) of the object.
string Description ;
The Description property provides a textual description of the object.