Balabit - AD objects for the SCB
Balabit SCB Solution · Config document · referenced from Active Directory and access control
<TEST_PASSWORD>, <SCB_SVC_PASSWORD>, <SCB_MAIL_PASSWORD>, <LXADMIN_PASSWORD>, <ROOT_PASSWORD>, <ADMIN_PASSWORD>); my notes held the real ones, and they are not reproduced. The two test-account tables of the notes contradict each other, see below.What the appliance needs in Active Directory, as the design specifies it, and the test accounts my working notes list per group: the service account that binds to the directory, the OU of the user accounts, the authorization groups that collect people, the role groups the appliance refers to, the mail account and the mail distribution group.
| Item | Value |
|---|---|
| Directory | ad.example.net, domain controllers dc1-a-vcad001 and dc1-a-vcad002 |
| Sources | My design document, version 0.5 of 2017-12-01 (draft), chapters 4.4 and 4.7; my working notes (two test-account tables and an LDAP fragment, none of them dated) |
| Created by | The AD administrators of the organisation; the material has no command or export of the objects as created, only the specification |
Lines starting with # | Mine: the DN sentences of the design, condensed, and the source of each block |
The listing
output 68 lines
# Design 4.4.1: service account scb_svc in CN=scb_svc,OU=Users_svc,DC=ad,DC=example,DC=net
# Design 4.4.2: user accounts in OU=Users_STD,DC=ad,DC=example,DC=net
# Design 4.4.3: authorization groups in OU=MA,OU=RBAC_GROUPS,OU=RBAC,DC=ad,DC=example,DC=net
| AD Group | Description |
| SCB_ADM_ORG | Group which will contain ORG user accounts which will be authorized as administrators of Balabit Shell Control Box. |
| SCB_OPS_ORG | Group which will contain ORG user accounts which will be authorized as operators of Balabit Shell Control Box. |
| SCB_USR_ORG | Group which will contain ORG user accounts which will be authorized to access target servers through Balabit SCB. |
| SCB_USR_PARTNER1 | Group which will contain PARTNER1 user accounts which will be authorized to access target servers through Balabit SCB. |
| SCB_USR_PARTNER2 | Group which will contain PARTNER2 user accounts which will be authorized to access target servers through Balabit SCB. |
| SCB_USR_GUESTS | Group which will contain GUESTS user accounts which will be authorized to access target servers through Balabit SCB. |
# Design 4.4.4: role groups in OU=MA,OU=RBAC_ROLES,OU=RBAC,DC=ad,DC=example,DC=net
| AD Group | Description |
| SCB_ADM | This group includes group SCB_ADM_ORG. |
| SCB_OPS | This group includes group SCB_OPS_ORG. |
| SCB_USERS_ORG | This group includes group SCB_USR_ORG. |
| SCB_USERS_PARTNER1 | This group includes group SCB_USR_PARTNER1. |
| SCB_USERS_PARTNER2 | This group includes group SCB_USR_PARTNER2. |
| SCB_USERS_GUESTS | This group includes group SCB_USR_GUESTS. |
# Design 4.7.1: mail account scb_mail in OU=msx_SVC,OU=Users_SVC,DC=ad,DC=example,DC=net
# Design 4.7.2: distribution group scb_mail_group in OU=MSX,OU=RBAC_GROUPS,OU=RBAC,DC=ad,DC=example,DC=net
| Person | AD Account |
| admin01 | admin01@ad.example.net |
| admin06 | admin06@ad.example.net |
| admin04 | admin04@ad.example.net |
| admin05 | admin05@ad.example.net |
| … | … |
# Notes: test accounts, first table
==============================================================================================================
User/Account Password Group membership Role Purpose
==============================================================================================================
test_scb1 <TEST_PASSWORD> SCB_USR_CLOUD_PARTNER1 SCB_USERS_CLOUD_PARTNER1 PARTNER1 CLOUD test user account through Balabit.
VPN for CLOUD_PARTNER1
--------------------------------------------------------------------------------------------------------------
test_scb2 <TEST_PASSWORD> SCB_USR_PARTNER4 SCB_USR_PARTNER4 PARTNER4 test user account through Balabit.
--------------------------------------------------------------------------------------------------------------
test_scb3 <TEST_PASSWORD> SCB_USR_PARTNER1 SCB_USERS_PARTNER1 PARTNER1 test user account through Balabit.
VPN for PARTNER1
--------------------------------------------------------------------------------------------------------------
test_scb4 <TEST_PASSWORD> SCB_USR_ORG SCB_USERS_ORG ORG test user account through Balabit.
VPN for ORG
--------------------------------------------------------------------------------------------------------------
test_scb5 <TEST_PASSWORD> SCB_USR_PARTNER3 SCB_USERS_PARTNER3 PARTNER3 test user account through Balabit.
VPN for PARTNER3
--------------------------------------------------------------------------------------------------------------
test_scb6 <TEST_PASSWORD> SCB_USR_PARTNER5 SCB_USERS_PARTNER5 PARTNER5 test user account through Balabit.
VPN_for PARTNER5
--------------------------------------------------------------------------------------------------------------
# Notes: test accounts and service accounts, second table
User - Password - Group Membership
test_scb1 - <TEST_PASSWORD> - SCB_ADM_ORG
test_scb2 - <TEST_PASSWORD> - SCB_OPS_ORG
test_scb3 - <TEST_PASSWORD> - SCB_USR_PARTNER1
test_scb4 - <TEST_PASSWORD> - SCB_USR_ORG
test_scb5 - <TEST_PASSWORD> - SCB_USR_PARTNER3
test66 - <TEST_PASSWORD> - SCB_USR_PARTNER4
test55 - <TEST_PASSWORD> - SCB_USR_PARTNER5
scb_svc - <SCB_SVC_PASSWORD>
scb_mail - <SCB_MAIL_PASSWORD>
lxadmin - <LXADMIN_PASSWORD>
root - <ROOT_PASSWORD>
admin - <ADMIN_PASSWORD>
# Notes: an LDAP setting without heading or date
BASE DN: ou=users_partner1,DC=ad,DC=example,DC=net
BIND DN: cn=balabit,ou=users_partner1,DC=ad,DC=example,DC=net
BIND PASSWORD:
USER ATTR. OF GROUP DNS: memberOf| Block | What to read in it |
|---|---|
Authorization groups (OU=RBAC_GROUPS) | Groups that hold people: SCB_ADM_ORG and SCB_OPS_ORG for the administrators and operators of the appliance, which are all from the organisation, and one SCB_USR_* group per company whose people pass through the appliance, plus SCB_USR_GUESTS |
Role groups (OU=RBAC_ROLES) | Groups that the appliance names: each contains exactly one authorization group. SCB_ADM and SCB_OPS are named on the AAA page, the SCB_USERS_* groups in the channel policies. SCB_USERS_GUESTS is named by no policy in the design |
scb_svc | The bind account of both the AAA settings and the LDAP server policy. The design writes OU=Users_svc, the configuration OU=USERS_SVC |
scb_mail, scb_mail_group | The account the appliance authenticates as to the mail server and sends from, and the distribution list that receives its mail; four administrators are named and the list ends with … |
| First test table | Group and role per test account, for the cloud team of partner 1, partner 4, partner 1, the organisation, partner 3 and partner 5. test_scb2 has SCB_USR_PARTNER4 in both columns, where the pattern of the other rows gives SCB_USERS_PARTNER4 as the role |
| Second test table | test_scb1 in SCB_ADM_ORG and test_scb2 in SCB_OPS_ORG, where the first table puts them in the cloud-team and partner 4 groups; partner 4 and 5 have the accounts test66 and test55 here instead of test_scb2 and test_scb6. The notes do not date either table, so I cannot say which state came later |
lxadmin, root, admin | root and admin are the local accounts of the appliance; lxadmin is not explained anywhere in the notes |
| LDAP fragment | A base DN ou=users_partner1 and a bind account cn=balabit in it: an LDAP setting for an OU of partner 1 users that appears nowhere else. Whether it was tried, and where, the notes do not say |
The groups for partners 3, 4 and 5 and for the cloud team of partner 1 are not in the design, which knows only the organisation, partner 1, partner 2 and guests; they came with the later partners. Of them, only SCB_USERS_PARTNER4 appears in a configuration, in the channel policy PARTNER4-TERMINAL-ONLY of the site 2 config.xml.