# OID to monitor Device trust certificate

**URL:** <https://community.f5.com/t/oid-to-monitor-device-trust-certificate/77284>\
**Category:** Technical Forums\
**Tags:** security, certficate, application-delivery\
**Created:** [July 22, 2026, 2:17pm UTC](https://community.f5.com/t/oid-to-monitor-device-trust-certificate/77284 "2026-07-22T14:17:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Blue\_whale](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@Blue\_whale](https://community.f5.com/u/Blue_whale)\
**Post date:** [July 22, 2026, 2:17pm UTC](https://community.f5.com/t/oid-to-monitor-device-trust-certificate/77284/1 "2026-07-22T14:17:11Z")

</div>

Hello Team ,

For device certificate expiry we use snmp OID - certsExpiration’: '.1.3.6.1.4.1.3375.2.100.1.0

Do we have similar OID to monitor Device trust certificate ?

---

<div class="post-metadata">

**Author:** ![JRahm](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/jrahm/32/3327_2.png) [@JRahm](https://community.f5.com/u/JRahm)\
**Post date:** [July 22, 2026, 11:02pm UTC](https://community.f5.com/t/oid-to-monitor-device-trust-certificate/77284/2 "2026-07-22T23:02:27Z")

</div>

I couldn’t find one, but you can create your own custom oid. Here’s how:

1. Use the script from&nbsp;[K000151455](https://my.f5.com/manage/s/article/K000151455) and place somewhere (I put it in _/config/check\_status.sh_)
  1. _chmod +x /config/check\_status.sh_ (changing to executable file)
  2. _chcon -t bin\_t /config/check\_trust.sh_ ( setting to a file type snmpd is allowed to execute)

2. Create file _/config/snmp/custom\_mib.tcl_ (see below)
3. Restart snmpd (_bigstart restart snmpd_)
4. grep for the the mibs being registered in the log file (_grep -i “custom mib” /var/log/snmpd.log_)
5. Test it out:

```auto
[root@bigip02:Active:In Sync] snmp # bigstart restart snmpd                                                                    
[root@bigip02:Active:In Sync] snmp # grep -i "custom mib" /var/log/snmpd.log
custom mib initialization completed. total 2 custom mib entry registered
[root@bigip02:Active:In Sync] snmp # snmpget -v2c -c public localhost .1.3.6.1.4.1.3375.2.100.5.0
F5-BIGIP-COMMON-MIB::bigipTrafficMgmt.100.5.0 = STRING: "Certificate is valid until Sep 30 21:46:25 2031 GMT (1895 Days remaining)"
[root@bigip02:Active:In Sync] snmp # snmpget -v2c -c public localhost .1.3.6.1.4.1.3375.2.100.6.0                              
F5-BIGIP-COMMON-MIB::bigipTrafficMgmt.100.6.0 = STRING: "1895"

```

Here’s the custom\_mib.tcl file (notice I set to .5 and .6 since it looks like you’re already using a custom mib space perhaps?)

```tcl
# /config/snmp/custom_mib.tcl
# .1.3.6.1.4.1.3375.2.100.5.0 -> trust cert, full status string
# .1.3.6.1.4.1.3375.2.100.6.0 -> trust cert, days remaining (int)

register_mib ".5" trust_cert_status string
register_mib ".6" trust_cert_days int

proc trust_cert_status {} {
    set status [catch {exec /config/check_trust.sh} result]
    if {$status != 0 || $result eq ""} {
        return "ERROR: check_trust.sh failed"
    }
    return [string trim $result]
}

proc trust_cert_days {} {
    set status [catch {exec /config/check_trust.sh} result]
    if {$status != 0} {
        return -1
    }
    if {[regexp {\(([0-9]+) Days remaining\)} $result -> days]} {
        return $days
    }
    return -1
}

```

(Tested on 21.x, but this has been possible for a long time. Here are [details from 13.1 user guide](https://techdocs.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-external-monitoring-implementations-13-1-0/13.html))

Hope this helps!
