LINUXOR.SK ... open source notes ...

Balabit - Certificate inventory

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Certificates and keys and Audit trails: encryption and replay

note<COUNTRY>, <RA UNIT>, <CA OPERATOR>, <CA OPERATOR UNIT>, <ROOT CA OPERATOR> and <ROOT CA UNIT> are placeholders for the country and the units and operators of the organisation's CA; "Example Org" stands for the organisation.

Every public certificate of my certificate folder, one block each: subject, issuer, validity, the extensions that matter and the key size. I generated the listing for this write-up from the certificate files with the command in its header; the private keys beside them were not opened.

ItemValue
Sourcethe public certificate files of my certificate folder for both sites
Made withopenssl x509 -noout -subject -issuer -dates -ext … plus the key size and signature algorithm lines of -text
SCB internal CAsite 1: CA, web server and TSA certificate of 9 August 2017; site 2: the same three of 6 March 2018
XCA, self-signedsite 1: SCB-AUDIT-SIGN, SCB-AUDIT-ENCRYPT (18 August 2017), SCB-AUDIT-ENCRYPT-admin01 (22 May 2018); site 2: the signing certificate (12 March 2018)
Organisation's CAthe cluster web certificate of 19 July 2017 and the two IPMI certificates of 8 January 2018, issued by "Internal CA"; the organisation's root CA certificate
Not in the folderthe certificate of the issuing "Internal CA", the IPMI certificates of 2017, the per-auditor certificates other than admin01's of site 1, every per-auditor certificate of site 2

The listing

output 191 lines
CERTIFICATE INVENTORY (generated from the public certificate files of the certificate folder with
openssl x509 -noout -subject -issuer -dates -ext basicConstraints,keyUsage,extendedKeyUsage,subjectAltName
and the key size and signature algorithm lines of -text; private keys were not opened)

======================================================================
 SCB internal CA, site 1 (CA certificate)
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net root CA
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net root CA
notBefore=Aug  9 06:01:49 2017 GMT
notAfter=Aug  4 06:01:49 2037 GMT
X509v3 Basic Constraints: critical
    CA:TRUE
X509v3 Key Usage: critical
    Certificate Sign, CRL Sign
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 SCB internal CA, site 1 (server certificate of the web interface)
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net root CA
notBefore=Aug  9 06:01:49 2017 GMT
notAfter=Aug  4 06:01:49 2037 GMT
X509v3 Subject Alternative Name:
    IP Address:10.11.16.81, DNS:dc1-s-xblm001.adm.example.net, DNS:10.11.16.81
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 SCB internal CA, site 1 (TSA certificate)
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net Time Stamping Authority
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net root CA
notBefore=Aug  9 06:01:49 2017 GMT
notAfter=Aug  4 06:01:49 2037 GMT
X509v3 Extended Key Usage: critical
    Time Stamping
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 SCB internal CA, site 2 (CA certificate)
======================================================================
subject=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net root CA
issuer=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net root CA
notBefore=Mar  6 13:26:26 2018 GMT
notAfter=Mar  1 13:26:26 2038 GMT
X509v3 Basic Constraints: critical
    CA:TRUE
X509v3 Key Usage: critical
    Certificate Sign, CRL Sign
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 SCB internal CA, site 2 (server certificate of the web interface)
======================================================================
subject=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net
issuer=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net root CA
notBefore=Mar  6 13:26:26 2018 GMT
notAfter=Mar  1 13:26:26 2038 GMT
X509v3 Subject Alternative Name:
    IP Address:10.12.16.81, DNS:dc2-s-xblb001.adm.example.net, DNS:10.12.16.81
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 SCB internal CA, site 2 (TSA certificate)
======================================================================
subject=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net Time Stamping Authority
issuer=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net root CA
notBefore=Mar  6 13:26:26 2018 GMT
notAfter=Mar  1 13:26:26 2038 GMT
X509v3 Extended Key Usage: critical
    Time Stamping
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 XCA, site 2 audit-trail signing certificate (folder _SCB_CA/SIGN-cert.pem)
======================================================================
subject=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, emailAddress=admin02@example.net
issuer=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, emailAddress=admin02@example.net
notBefore=Mar 12 10:49:00 2018 GMT
notAfter=Mar 12 10:49:00 2028 GMT
X509v3 Basic Constraints: critical
    CA:FALSE
X509v3 Key Usage:
    Digital Signature, Non Repudiation, Key Encipherment
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 XCA, site 1 audit-trail signing certificate SCB-AUDIT-SIGN
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net
notBefore=Aug 18 10:52:00 2017 GMT
notAfter=Aug 18 10:52:00 2027 GMT
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 XCA, site 1 audit-trail encryption certificate SCB-AUDIT-ENCRYPT
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net
notBefore=Aug 18 10:48:00 2017 GMT
notAfter=Aug 18 10:48:00 2027 GMT
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 XCA, site 1 per-auditor encryption certificate SCB-AUDIT-ENCRYPT-admin01
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, emailAddress=admin01@example.net
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, emailAddress=admin01@example.net
notBefore=May 22 10:30:00 2018 GMT
notAfter=May 22 10:30:00 2028 GMT
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 Organisation CA, web certificate requested for the SCB cluster (adm zone)
======================================================================
subject=C=<COUNTRY>, O=Example Org, OU=example.net, OU=<RA UNIT>, CN=dc1-s-xblm001.adm.example.net, L=Site 1, emailAddress=admin02@example.net
issuer=C=<COUNTRY>, O=<CA OPERATOR>, OU=<CA OPERATOR UNIT>, CN=Internal CA
notBefore=Jul 19 13:50:56 2017 GMT
notAfter=Jul 19 23:59:59 2018 GMT
X509v3 Key Usage: critical
    Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
    TLS Web Client Authentication, TLS Web Server Authentication
X509v3 Basic Constraints:
    CA:FALSE
X509v3 Subject Alternative Name:
    DNS:dc1-s-xblm001.adm.example.net, DNS:dc1-s-xblb001.adm.example.net, DNS:scb.example.net
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (4096 bit)

======================================================================
 Organisation CA, IPMI web certificate of node A (mgmt zone)
======================================================================
subject=C=<COUNTRY>, O=Example Org, OU=example.net, OU=<RA UNIT>, CN=dc1-a-ablb001m.mgmt.example.net, L=Site 1, emailAddress=admin02@example.net
issuer=C=<COUNTRY>, O=<CA OPERATOR>, OU=<CA OPERATOR UNIT>, CN=Internal CA
notBefore=Jan  8 08:18:03 2018 GMT
notAfter=Jan  8 23:59:59 2019 GMT
X509v3 Key Usage: critical
    Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
    TLS Web Client Authentication, TLS Web Server Authentication
X509v3 Basic Constraints:
    CA:FALSE
X509v3 Subject Alternative Name:
    DNS:dc1-a-ablb001m.mgmt.example.net
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 Organisation CA, IPMI web certificate of node B (mgmt zone)
======================================================================
subject=C=<COUNTRY>, O=Example Org, OU=example.net, OU=<RA UNIT>, CN=dc1-b-ablb001m.mgmt.example.net, L=Site 1, emailAddress=admin02@example.net
issuer=C=<COUNTRY>, O=<CA OPERATOR>, OU=<CA OPERATOR UNIT>, CN=Internal CA
notBefore=Jan  8 08:17:01 2018 GMT
notAfter=Jan  8 23:59:59 2019 GMT
X509v3 Key Usage: critical
    Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
    TLS Web Client Authentication, TLS Web Server Authentication
X509v3 Basic Constraints:
    CA:FALSE
X509v3 Subject Alternative Name:
    DNS:dc1-b-ablb001m.mgmt.example.net
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)

======================================================================
 Organisation root CA certificate kept beside them
======================================================================
subject=C=<COUNTRY>, O=<ROOT CA OPERATOR>, OU=<ROOT CA UNIT>, CN=Internal Root CA 1
issuer=C=<COUNTRY>, O=<ROOT CA OPERATOR>, OU=<ROOT CA UNIT>, CN=Internal Root CA 1
notBefore=Nov 15 12:28:30 2007 GMT
notAfter=Nov 15 23:59:59 2027 GMT
X509v3 Key Usage: critical
    Digital Signature, Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
    CA:TRUE, pathlen:1
Signature Algorithm: sha1WithRSAEncryption
Public-Key: (2048 bit)
BlockWhat it shows
SCB internal CA, site 1made by the SCB itself on 9 August 2017, valid 20 years less five days. The common names say dc1-s-xblm001, the cluster's management name of the design's DNS records; chapter 7 of the design prints dc1-s-xblb001 on the same page
Server certificate, site 1the address 10.11.16.81 is in the alternative names twice, once as IP Address: and once as DNS:; the name dc1-s-xblb001… and the user-access name scb.example.net are not in it
TSA certificateTime Stamping as a critical extended key usage, the certificate the organisation's CA could not issue
SCB internal CA, site 2the same three certificates with L=Site 2 and the site 2 cluster's name, made on 6 March 2018
XCA signing certificate, site 2stored as SIGN-cert.pem under _SCB_CA; unlike the site 1 ones it carries admin02's e-mail address, CA:FALSE and a key usage, so, as I read it, it was made from another XCA template
SCB-AUDIT-SIGN, SCB-AUDIT-ENCRYPT, site 1self-signed, ten years, no extensions printed; the dates match the expiry dates in the design
SCB-AUDIT-ENCRYPT-admin01the only per-auditor certificate in the folder, made on 22 May 2018, nine months after the shared ones
Organisation CA, cluster web certificateRSA 4096, one year, client and server authentication, three DNS names; issued three weeks before the SCB made its own CA
Organisation CA, IPMI certificatesRSA 2048, one year from 8 January 2018
Organisation root CAInternal Root CA 1, 2007 to 2027, pathlen:1, signed with SHA-1

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
CA, server and TSA certificates generated on the SCBstill possible; the vendor now recommends certificates from your own PKI, because certificates generated on the appliance cannot be revoked
Server and TSA certificate from one CA; TSA with critical Time Stampingboth rules unchanged; new is the rule that the TSA key usage be non-repudiation and digital signature only (the inventory does not print the key usage of the SCB's TSA certificates)
Audit-trail signing certificates without an extended key usageSPS 9.0 requires the signing certificate's extended key usage to be "Sign (downloadable) executable code"
RSA 2048 and SHA-256 for every TLS certificate; root CA signed with SHA-1since 6.10.0 an upgrade is blocked by RSA keys under 2048 bits and by SHA-1 or MD5 signatures on certificates other than root CAs; nothing in this inventory falls under that

Of these certificates, the audit-trail signing certificates are the ones that would have to be made again for SPS 9.0.

← solutionz