LINUXOR.SK ... open source notes ...

Balabit - Default audit policy (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Audit trails: encryption and replay and Connection and channel policies

noteThis is the site 1 policy of December 2017, with one encryption certificate. The site 2 cluster's exported configuration of September 2018 has six encryption certificates in the same policy, see config.xml audit policy (site 2). The design does not show whether site 1 changed the same way when the per-auditor keys were made in 2018.

The built-in audit policy default as configured on the site 1 cluster: every audit trail is encrypted with the certificate SCB-AUDIT-ENCRYPT, timestamped and signed with the key SCB-AUDIT-SIGN. Every connection uses this policy, so it governs every audited channel.

ItemValue
WherePolicies > Audit Policies > default
Clusterdc1-s-xblb001, site 1
Firmware at the time5 LTS (5.0.3)
Used byevery connection; the policy is not changed per partner
Keysmade in XCA, see XCA and GPG keys
Sourcedesign document v0.5 of 2017-12-01, chapter 7.4.1

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.4.1
Policies > Audit Policies > default > ENCRYPTION / ENABLE ENCRYPTION = Yes
Policies > Audit Policies > default > ENCRYPTION / ENCRYPTION CERT (X.509 RSA) = SCB-AUDIT-ENCRYPT certificate
Policies > Audit Policies > default > ENCRYPTION / FOUR-EYES CERT (X.509 RSA) = 
Policies > Audit Policies > default > ENCRYPTION / ENCRYPT UPSTREAM TRAFFIC WITH DIFFERENT CERTIFICATES = No

Policies > Audit Policies > default > TIMESTAMPING / ENABLE TIMESTAMPING = Yes

Policies > Audit Policies > default > SIGNING / ENABLE SIGNING = Yes
Policies > Audit Policies > default > SIGNING / X.509 CERTIFICATE = SCB-AUDIT-SIGN certificate
Policies > Audit Policies > default > SIGNING / PRIVATE KEY = SCB-AUDIT-SIGN private key
FieldWhat it means
ENCRYPTION CERT (X.509 RSA)only the certificate, that is the public key, is on the SCB. Whoever holds the private key of SCB-AUDIT-ENCRYPT can decrypt; as I understand it, the SCB itself cannot replay an encrypted trail without it
FOUR-EYES CERT (X.509 RSA)empty: no second certificate whose key would also be needed to decrypt. The four-eyes functions of the SCB were not used
ENCRYPT UPSTREAM TRAFFIC WITH DIFFERENT CERTIFICATESNo: what the user typed and what the server sent are encrypted with the same certificate. With Yes the upstream part (keystrokes, passwords) would need another key, which the design describes in its introduction and did not use
ENABLE TIMESTAMPINGtimestamps from a TSA; the global options of every protocol set the timestamping to Local, the SCB's own TSA certificate, see SSL certificate (site 1)
SIGNINGthe SCB signs the trail with the private key of SCB-AUDIT-SIGN, which had to be uploaded together with its certificate. The global options of every protocol set a signing interval of 30 seconds

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
One encryption certificate, no four-eyes certificatethe same model, now named "Encrypt with a single certificate", "Encrypt separately with multiple certificates" and "Encrypt jointly with two certificates" (four-eyes in auditing); up to 8 lines of certificate pairs per policy
ENCRYPT UPSTREAM TRAFFIC WITH DIFFERENT CERTIFICATES = Nothe vendor's security checklist, as SCB 5's already did, recommends encrypting the upstream traffic with a separate certificate, because in RDP the password typed on the Windows login screen is visible in the trail; command detection in indexing then needs the upstream keys
Timestamping local, signing interval 30 sunchanged; the interval may be 10 to 100 000 seconds and applies to both timestamping and signing
Signing with SCB-AUDIT-SIGNstill supported; the signing certificate must now carry the extended key usage "Sign (downloadable) executable code"

The upstream setting is the one choice here that went against the vendor's advice then and now.

← solutionz