LINUXOR.SK ... open source notes ...

Balabit - AAA (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Active Directory and access control

notepassword_for_scb_svc was a placeholder already in my design document; the real bind password was never written into it. "No certificate is required" means the certificates of the domain controllers were not verified.

Who may log in to the web interface of the appliance and what each user may see and change: the web users are authenticated against Active Directory over LDAPS with the service account scb_svc, their AD group memberships (nested ones included) decide their rights, and every configuration change needs a commit message.

ItemValue
WhereSCB web interface, AAA > Settings and AAA > Access Control
Clusterdc1-s-xblb001, site 1
Firmware at the time5 LTS (5.0.3)
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapters 7.3.1 to 7.3.3
Directoryad.example.net, domain controllers dc1-a-vcad001 (10.11.16.209) and dc1-a-vcad002 (10.11.16.210), LDAPS on TCP 636
Groups in ADAD objects for the SCB

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.3.1 to 7.3.3

AAA > Settings > Authentication settings / AUTHENTICATION METHOD = Password provided by database
AAA > Settings > Authentication settings / USER DATABASE = LDAP
AAA > Settings > Authentication settings / SERVER ADDRESS = Address: dc1-a-vcad001.adm.example.net / Port: 636 / Address: dc1-a-vcad002.adm.example.net / Port: 636
AAA > Settings > Authentication settings / TYPE = Active Directory
AAA > Settings > Authentication settings / BASE DN = DC=ad,DC=example,DC=net
AAA > Settings > Authentication settings / BIND DN = CN=scb_svc,OU=USERS_SVC,DC=ad,DC=example,DC=net
AAA > Settings > Authentication settings / BIND PASSWORD = password_for_scb_svc
AAA > Settings > Authentication settings / USE ATTR. OF GROUP DNS = memberOf
AAA > Settings > Authentication settings / ENABLE NESTED GROUPS = Yes
AAA > Settings > Authentication settings / ENCRYPTION / SERVER CERTIFICATE CHECK / AUTHENTICATE CLIENT = TLS / No certificate is required / No

AAA > Settings > Accounting settings / REQUIRE COMMIT LOG = Yes

AAA > Access Control > basic-view / Object = Basic Settings
AAA > Access Control > basic-view / Type = read
AAA > Access Control > basic-write / Object = Basic Settings
AAA > Access Control > basic-write / Type = read and write/perform
AAA > Access Control > auth-view / Object = AAA
AAA > Access Control > auth-view / Type = read
AAA > Access Control > auth-write / Object = AAA
AAA > Access Control > auth-write / Type = read and write/perform
AAA > Access Control > search / Object = Search
AAA > Access Control > search / Type = read
AAA > Access Control > changelog / Object = AAA/Accounting
AAA > Access Control > changelog / Type = read
AAA > Access Control > policies-view / Object = Policies
AAA > Access Control > policies-view / Type = read
AAA > Access Control > policies-write / Object = Policies
AAA > Access Control > policies-write / Type = read and write/perform
AAA > Access Control > ssh-view / Object = SSH Control
AAA > Access Control > ssh-view / Type = read
AAA > Access Control > ssh-write / Object = SSH Control
AAA > Access Control > ssh-write / Type = read and write/perform
AAA > Access Control > rdp-view / Object = RDP Control
AAA > Access Control > rdp-view / Type = read
AAA > Access Control > rdp-write / Object = RDP Control
AAA > Access Control > rdp-write / Type = read and write/perform
AAA > Access Control > telnet-view / Object = TELNET Control
AAA > Access Control > telnet-view / Type = read
AAA > Access Control > telnet-write / Object = TELNET Control
AAA > Access Control > telnet-write / Type = read and write/perform
AAA > Access Control > vnc-view / Object = VNC Control
AAA > Access Control > vnc-view / Type = read
AAA > Access Control > vnc-write / Object = VNC Control
AAA > Access Control > vnc-write / Type = read and write/perform
AAA > Access Control > indexing / Object = Search/Search / Indexer/Audit Player communication
AAA > Access Control > indexing / Type = read and write/perform
AAA > Access Control > ica-view / Object = ICA Control
AAA > Access Control > ica-view / Type = read
AAA > Access Control > ica-write / Object = ICA Control
AAA > Access Control > ica-write / Type = read and write/perform
AAA > Access Control > api / Object = Access RPC API
AAA > Access Control > api / Type = read and write/perform
AAA > Access Control > http-view / Object = HTTP Control
AAA > Access Control > http-view / Type = read
AAA > Access Control > http-write / Object = HTTP Control
AAA > Access Control > http-write / Type = read and write/perform
AAA > Access Control > indexer-view / Object = Indexer
AAA > Access Control > indexer-view / Type = read
AAA > Access Control > indexer-write / Object = Indexer
AAA > Access Control > indexer-write / Type = read and write/perform
AAA > Access Control > admin-write / Object = All
AAA > Access Control > admin-write / Type = read and write/perform
AAA > Access Control > admin-read / Object = All
AAA > Access Control > admin-read / Type = read
AAA > Access Control > SCB_ADM / Object = All
AAA > Access Control > SCB_ADM / Type = read and write/perform
AAA > Access Control > SCB_OPS / Object = All
AAA > Access Control > SCB_OPS / Type = read
AAA > Access Control > SCB_OPS / Object = System debug / Basic Settings/Troubleshooting
AAA > Access Control > SCB_OPS / Type = read and write/perform
SettingWhat it means here
Password provided by database, LDAP, Active DirectoryA web user types the AD password, the appliance checks it against AD. When LDAP is the user database, the local users are switched off except admin, which stays as the way in when AD does not answer
Two servers on 636If the first domain controller does not answer, the second is tried
Bind DN scb_svcThe service account that searches the directory. The design's chapter 4.4.1 writes its OU as OU=Users_svc; here it is OU=USERS_SVC. AD does not care about the case of DNs, so both name the same object
memberOf, nested groups YesThe groups are read from the user's memberOf attribute, and groups inside groups count, which is what lets SCB_ADM_ORG inside SCB_ADM work
TLS, "No certificate is required", authenticate client NoThe connection is encrypted (LDAPS), but the domain controller's certificate is accepted without any check, and the appliance shows no client certificate
Require commit log YesEvery change in the web interface asks for a comment, which the changelog page shows later
basic-view to admin-readThe groups the appliance creates by itself, with their default rights; they were left as they are
SCB_ADM: All, read and writeThe AD role group of the administrators gets everything
SCB_OPS: All read, plus System debug and Troubleshooting writeThe operators see everything and change nothing, except that they can switch on debug mode and use the troubleshooting page, for example to collect a support bundle

The exported config.xml of the site 2 cluster (2018-09-17, element <aaa>) has the same backend and the same access control list, with one difference, the commit log. It authenticates against the site 1 domain controllers dc1-a-vcad001 and dc1-a-vcad002, as here; the XML writes TLS and "No certificate is required" as <encryption choice="ssl"> and <server_cert_check choice="never"/>. But it has <require_commitlog enabled="no"/>, so in site 2 changes needed no comment. Its only local user is admin, whose password was set on 2018-01-08 (pwcreated), and the built-in groups have no members.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
AAA > Settings, LDAP, Active DirectoryConfigured under Users & Access Control > Login options: first an AD/LDAP server, then a login method; "Enable nested groups" is still there, with the warning that nested groups can slow the query; the group attribute is still for example memberOf
TLS on 636, "No certificate is required"636 for TLS, 389 for STARTTLS. The server certificate is verified against a trust store, and the address must then be a name or address present in the certificate. Since 6.0.4 and 6.5.0 certificates with SHA-1 signatures are not trusted for AD or LDAP authentication. Whether "no check" can still be selected the 9.0 guide does not say
Local admin as last resortUnchanged: local users including admin exist by default, admin cannot be deleted and is subject to the brute-force protection
Require commit log; built-in groupsBoth remain

The structure of this page survived. Its weak setting, no verification of the domain controllers, now has a documented replacement in the trust store, and SHA-1 signed domain-controller certificates would no longer be trusted after an upgrade.

← solutionz