LINUXOR.SK ... open source notes ...

Balabit - AD objects for the SCB

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Active Directory and access control

noteEvery password in this listing is a placeholder (<TEST_PASSWORD>, <SCB_SVC_PASSWORD>, <SCB_MAIL_PASSWORD>, <LXADMIN_PASSWORD>, <ROOT_PASSWORD>, <ADMIN_PASSWORD>); my notes held the real ones, and they are not reproduced. The two test-account tables of the notes contradict each other, see below.

What the appliance needs in Active Directory, as the design specifies it, and the test accounts my working notes list per group: the service account that binds to the directory, the OU of the user accounts, the authorization groups that collect people, the role groups the appliance refers to, the mail account and the mail distribution group.

ItemValue
Directoryad.example.net, domain controllers dc1-a-vcad001 and dc1-a-vcad002
SourcesMy design document, version 0.5 of 2017-12-01 (draft), chapters 4.4 and 4.7; my working notes (two test-account tables and an LDAP fragment, none of them dated)
Created byThe AD administrators of the organisation; the material has no command or export of the objects as created, only the specification
Lines starting with #Mine: the DN sentences of the design, condensed, and the source of each block

The listing

output 68 lines
# Design 4.4.1: service account scb_svc in CN=scb_svc,OU=Users_svc,DC=ad,DC=example,DC=net
# Design 4.4.2: user accounts in OU=Users_STD,DC=ad,DC=example,DC=net
# Design 4.4.3: authorization groups in OU=MA,OU=RBAC_GROUPS,OU=RBAC,DC=ad,DC=example,DC=net
| AD Group | Description |
| SCB_ADM_ORG | Group which will contain ORG user accounts which will be authorized as administrators of Balabit Shell Control Box. |
| SCB_OPS_ORG | Group which will contain ORG user accounts which will be authorized as operators of Balabit Shell Control Box. |
| SCB_USR_ORG | Group which will contain ORG user accounts which will be authorized to access target servers through Balabit SCB. |
| SCB_USR_PARTNER1 | Group which will contain PARTNER1 user accounts which will be authorized to access target servers through Balabit SCB. |
| SCB_USR_PARTNER2 | Group which will contain PARTNER2 user accounts which will be authorized to access target servers through Balabit SCB. |
| SCB_USR_GUESTS | Group which will contain GUESTS user accounts which will be authorized to access target servers through Balabit SCB. |
# Design 4.4.4: role groups in OU=MA,OU=RBAC_ROLES,OU=RBAC,DC=ad,DC=example,DC=net
| AD Group | Description |
| SCB_ADM | This group includes group SCB_ADM_ORG. |
| SCB_OPS | This group includes group SCB_OPS_ORG. |
| SCB_USERS_ORG | This group includes group SCB_USR_ORG. |
| SCB_USERS_PARTNER1 | This group includes group SCB_USR_PARTNER1. |
| SCB_USERS_PARTNER2 | This group includes group SCB_USR_PARTNER2. |
| SCB_USERS_GUESTS | This group includes group SCB_USR_GUESTS. |
# Design 4.7.1: mail account scb_mail in OU=msx_SVC,OU=Users_SVC,DC=ad,DC=example,DC=net
# Design 4.7.2: distribution group scb_mail_group in OU=MSX,OU=RBAC_GROUPS,OU=RBAC,DC=ad,DC=example,DC=net
| Person | AD Account |
| admin01 | admin01@ad.example.net  |
| admin06 | admin06@ad.example.net |
| admin04 | admin04@ad.example.net  |
| admin05 | admin05@ad.example.net  |
| … | … |
# Notes: test accounts, first table
==============================================================================================================
User/Account	Password	  Group membership	  Role	                   Purpose
==============================================================================================================
test_scb1	<TEST_PASSWORD>     SCB_USR_CLOUD_PARTNER1      SCB_USERS_CLOUD_PARTNER1     PARTNER1 CLOUD test user account through Balabit.
                                  VPN for CLOUD_PARTNER1
--------------------------------------------------------------------------------------------------------------
test_scb2	<TEST_PASSWORD>       SCB_USR_PARTNER4	          SCB_USR_PARTNER4            PARTNER4 test user account through Balabit.
--------------------------------------------------------------------------------------------------------------
test_scb3	<TEST_PASSWORD>	  SCB_USR_PARTNER1           SCB_USERS_PARTNER1          PARTNER1 test user account through Balabit.
                                  VPN for PARTNER1
--------------------------------------------------------------------------------------------------------------
test_scb4	<TEST_PASSWORD>	  SCB_USR_ORG           SCB_USERS_ORG          ORG test user account through Balabit.
                                  VPN for ORG
--------------------------------------------------------------------------------------------------------------
test_scb5       <TEST_PASSWORD>          SCB_USR_PARTNER3          SCB_USERS_PARTNER3         PARTNER3 test user account through Balabit.
                                  VPN for PARTNER3
--------------------------------------------------------------------------------------------------------------
test_scb6       <TEST_PASSWORD>  SCB_USR_PARTNER5         SCB_USERS_PARTNER5        PARTNER5 test user account through Balabit.
                                  VPN_for PARTNER5
--------------------------------------------------------------------------------------------------------------
# Notes: test accounts and service accounts, second table
User        -   Password             -   Group Membership
test_scb1   -   <TEST_PASSWORD>      -   SCB_ADM_ORG
test_scb2   -   <TEST_PASSWORD>      -   SCB_OPS_ORG
test_scb3   -   <TEST_PASSWORD>      -   SCB_USR_PARTNER1
test_scb4   -   <TEST_PASSWORD>      -   SCB_USR_ORG
test_scb5   -   <TEST_PASSWORD>      -   SCB_USR_PARTNER3
test66      -   <TEST_PASSWORD>      -   SCB_USR_PARTNER4
test55      -   <TEST_PASSWORD>      -   SCB_USR_PARTNER5

scb_svc     -   <SCB_SVC_PASSWORD>
scb_mail    -   <SCB_MAIL_PASSWORD>
lxadmin     -   <LXADMIN_PASSWORD>

root        -   <ROOT_PASSWORD>
admin       -   <ADMIN_PASSWORD>
# Notes: an LDAP setting without heading or date
BASE DN: ou=users_partner1,DC=ad,DC=example,DC=net
BIND DN: cn=balabit,ou=users_partner1,DC=ad,DC=example,DC=net
BIND PASSWORD:
USER ATTR. OF GROUP DNS: memberOf
BlockWhat to read in it
Authorization groups (OU=RBAC_GROUPS)Groups that hold people: SCB_ADM_ORG and SCB_OPS_ORG for the administrators and operators of the appliance, which are all from the organisation, and one SCB_USR_* group per company whose people pass through the appliance, plus SCB_USR_GUESTS
Role groups (OU=RBAC_ROLES)Groups that the appliance names: each contains exactly one authorization group. SCB_ADM and SCB_OPS are named on the AAA page, the SCB_USERS_* groups in the channel policies. SCB_USERS_GUESTS is named by no policy in the design
scb_svcThe bind account of both the AAA settings and the LDAP server policy. The design writes OU=Users_svc, the configuration OU=USERS_SVC
scb_mail, scb_mail_groupThe account the appliance authenticates as to the mail server and sends from, and the distribution list that receives its mail; four administrators are named and the list ends with …
First test tableGroup and role per test account, for the cloud team of partner 1, partner 4, partner 1, the organisation, partner 3 and partner 5. test_scb2 has SCB_USR_PARTNER4 in both columns, where the pattern of the other rows gives SCB_USERS_PARTNER4 as the role
Second test tabletest_scb1 in SCB_ADM_ORG and test_scb2 in SCB_OPS_ORG, where the first table puts them in the cloud-team and partner 4 groups; partner 4 and 5 have the accounts test66 and test55 here instead of test_scb2 and test_scb6. The notes do not date either table, so I cannot say which state came later
lxadmin, root, adminroot and admin are the local accounts of the appliance; lxadmin is not explained anywhere in the notes
LDAP fragmentA base DN ou=users_partner1 and a bind account cn=balabit in it: an LDAP setting for an OU of partner 1 users that appears nowhere else. Whether it was tried, and where, the notes do not say

The groups for partners 3, 4 and 5 and for the cloud team of partner 1 are not in the design, which knows only the organisation, partner 1, partner 2 and guests; they came with the later partners. Of them, only SCB_USERS_PARTNER4 appears in a configuration, in the channel policy PARTNER4-TERMINAL-ONLY of the site 2 config.xml.

← solutionz