Balabit - Default audit policy (site 1)
Balabit SCB Solution · Config document · referenced from Audit trails: encryption and replay and Connection and channel policies
noteThis is the site 1 policy of December 2017, with one encryption certificate. The site 2 cluster's exported configuration of September 2018 has six encryption certificates in the same policy, see config.xml audit policy (site 2). The design does not show whether site 1 changed the same way when the per-auditor keys were made in 2018.
The built-in audit policy default as configured on the site 1 cluster: every audit trail is encrypted with the certificate SCB-AUDIT-ENCRYPT, timestamped and signed with the key SCB-AUDIT-SIGN. Every connection uses this policy, so it governs every audited channel.
| Item | Value |
|---|---|
| Where | Policies > Audit Policies > default |
| Cluster | dc1-s-xblb001, site 1 |
| Firmware at the time | 5 LTS (5.0.3) |
| Used by | every connection; the policy is not changed per partner |
| Keys | made in XCA, see XCA and GPG keys |
| Source | design document v0.5 of 2017-12-01, chapter 7.4.1 |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.4.1 Policies > Audit Policies > default > ENCRYPTION / ENABLE ENCRYPTION = Yes Policies > Audit Policies > default > ENCRYPTION / ENCRYPTION CERT (X.509 RSA) = SCB-AUDIT-ENCRYPT certificate Policies > Audit Policies > default > ENCRYPTION / FOUR-EYES CERT (X.509 RSA) = Policies > Audit Policies > default > ENCRYPTION / ENCRYPT UPSTREAM TRAFFIC WITH DIFFERENT CERTIFICATES = No Policies > Audit Policies > default > TIMESTAMPING / ENABLE TIMESTAMPING = Yes Policies > Audit Policies > default > SIGNING / ENABLE SIGNING = Yes Policies > Audit Policies > default > SIGNING / X.509 CERTIFICATE = SCB-AUDIT-SIGN certificate Policies > Audit Policies > default > SIGNING / PRIVATE KEY = SCB-AUDIT-SIGN private key
| Field | What it means |
|---|---|
ENCRYPTION CERT (X.509 RSA) | only the certificate, that is the public key, is on the SCB. Whoever holds the private key of SCB-AUDIT-ENCRYPT can decrypt; as I understand it, the SCB itself cannot replay an encrypted trail without it |
FOUR-EYES CERT (X.509 RSA) | empty: no second certificate whose key would also be needed to decrypt. The four-eyes functions of the SCB were not used |
ENCRYPT UPSTREAM TRAFFIC WITH DIFFERENT CERTIFICATES | No: what the user typed and what the server sent are encrypted with the same certificate. With Yes the upstream part (keystrokes, passwords) would need another key, which the design describes in its introduction and did not use |
ENABLE TIMESTAMPING | timestamps from a TSA; the global options of every protocol set the timestamping to Local, the SCB's own TSA certificate, see SSL certificate (site 1) |
SIGNING | the SCB signs the trail with the private key of SCB-AUDIT-SIGN, which had to be uploaded together with its certificate. The global options of every protocol set a signing interval of 30 seconds |
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| One encryption certificate, no four-eyes certificate | the same model, now named "Encrypt with a single certificate", "Encrypt separately with multiple certificates" and "Encrypt jointly with two certificates" (four-eyes in auditing); up to 8 lines of certificate pairs per policy |
ENCRYPT UPSTREAM TRAFFIC WITH DIFFERENT CERTIFICATES = No | the vendor's security checklist, as SCB 5's already did, recommends encrypting the upstream traffic with a separate certificate, because in RDP the password typed on the Windows login screen is visible in the trail; command detection in indexing then needs the upstream keys |
| Timestamping local, signing interval 30 s | unchanged; the interval may be 10 to 100 000 seconds and applies to both timestamping and signing |
Signing with SCB-AUDIT-SIGN | still supported; the signing certificate must now carry the extended key usage "Sign (downloadable) executable code" |
The upstream setting is the one choice here that went against the vendor's advice then and now.