Balabit - Certificate inventory
Balabit SCB Solution · Config document · referenced from Certificates and keys and Audit trails: encryption and replay
note
<COUNTRY>, <RA UNIT>, <CA OPERATOR>, <CA OPERATOR UNIT>, <ROOT CA OPERATOR> and <ROOT CA UNIT> are placeholders for the country and the units and operators of the organisation's CA; "Example Org" stands for the organisation.Every public certificate of my certificate folder, one block each: subject, issuer, validity, the extensions that matter and the key size. I generated the listing for this write-up from the certificate files with the command in its header; the private keys beside them were not opened.
| Item | Value |
|---|---|
| Source | the public certificate files of my certificate folder for both sites |
| Made with | openssl x509 -noout -subject -issuer -dates -ext … plus the key size and signature algorithm lines of -text |
| SCB internal CA | site 1: CA, web server and TSA certificate of 9 August 2017; site 2: the same three of 6 March 2018 |
| XCA, self-signed | site 1: SCB-AUDIT-SIGN, SCB-AUDIT-ENCRYPT (18 August 2017), SCB-AUDIT-ENCRYPT-admin01 (22 May 2018); site 2: the signing certificate (12 March 2018) |
| Organisation's CA | the cluster web certificate of 19 July 2017 and the two IPMI certificates of 8 January 2018, issued by "Internal CA"; the organisation's root CA certificate |
| Not in the folder | the certificate of the issuing "Internal CA", the IPMI certificates of 2017, the per-auditor certificates other than admin01's of site 1, every per-auditor certificate of site 2 |
The listing
output 191 lines
CERTIFICATE INVENTORY (generated from the public certificate files of the certificate folder with
openssl x509 -noout -subject -issuer -dates -ext basicConstraints,keyUsage,extendedKeyUsage,subjectAltName
and the key size and signature algorithm lines of -text; private keys were not opened)
======================================================================
SCB internal CA, site 1 (CA certificate)
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net root CA
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net root CA
notBefore=Aug 9 06:01:49 2017 GMT
notAfter=Aug 4 06:01:49 2037 GMT
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
SCB internal CA, site 1 (server certificate of the web interface)
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net root CA
notBefore=Aug 9 06:01:49 2017 GMT
notAfter=Aug 4 06:01:49 2037 GMT
X509v3 Subject Alternative Name:
IP Address:10.11.16.81, DNS:dc1-s-xblm001.adm.example.net, DNS:10.11.16.81
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
SCB internal CA, site 1 (TSA certificate)
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net Time Stamping Authority
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, CN=dc1-s-xblm001.adm.example.net root CA
notBefore=Aug 9 06:01:49 2017 GMT
notAfter=Aug 4 06:01:49 2037 GMT
X509v3 Extended Key Usage: critical
Time Stamping
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
SCB internal CA, site 2 (CA certificate)
======================================================================
subject=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net root CA
issuer=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net root CA
notBefore=Mar 6 13:26:26 2018 GMT
notAfter=Mar 1 13:26:26 2038 GMT
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
SCB internal CA, site 2 (server certificate of the web interface)
======================================================================
subject=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net
issuer=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net root CA
notBefore=Mar 6 13:26:26 2018 GMT
notAfter=Mar 1 13:26:26 2038 GMT
X509v3 Subject Alternative Name:
IP Address:10.12.16.81, DNS:dc2-s-xblb001.adm.example.net, DNS:10.12.16.81
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
SCB internal CA, site 2 (TSA certificate)
======================================================================
subject=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net Time Stamping Authority
issuer=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, CN=dc2-s-xblb001.adm.example.net root CA
notBefore=Mar 6 13:26:26 2018 GMT
notAfter=Mar 1 13:26:26 2038 GMT
X509v3 Extended Key Usage: critical
Time Stamping
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
XCA, site 2 audit-trail signing certificate (folder _SCB_CA/SIGN-cert.pem)
======================================================================
subject=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, emailAddress=admin02@example.net
issuer=C=<COUNTRY>, L=Site 2, O=Example Org, OU=example.net, emailAddress=admin02@example.net
notBefore=Mar 12 10:49:00 2018 GMT
notAfter=Mar 12 10:49:00 2028 GMT
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Key Usage:
Digital Signature, Non Repudiation, Key Encipherment
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
XCA, site 1 audit-trail signing certificate SCB-AUDIT-SIGN
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net
notBefore=Aug 18 10:52:00 2017 GMT
notAfter=Aug 18 10:52:00 2027 GMT
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
XCA, site 1 audit-trail encryption certificate SCB-AUDIT-ENCRYPT
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net
notBefore=Aug 18 10:48:00 2017 GMT
notAfter=Aug 18 10:48:00 2027 GMT
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
XCA, site 1 per-auditor encryption certificate SCB-AUDIT-ENCRYPT-admin01
======================================================================
subject=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, emailAddress=admin01@example.net
issuer=C=<COUNTRY>, L=Site 1, O=Example Org, OU=example.net, emailAddress=admin01@example.net
notBefore=May 22 10:30:00 2018 GMT
notAfter=May 22 10:30:00 2028 GMT
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
Organisation CA, web certificate requested for the SCB cluster (adm zone)
======================================================================
subject=C=<COUNTRY>, O=Example Org, OU=example.net, OU=<RA UNIT>, CN=dc1-s-xblm001.adm.example.net, L=Site 1, emailAddress=admin02@example.net
issuer=C=<COUNTRY>, O=<CA OPERATOR>, OU=<CA OPERATOR UNIT>, CN=Internal CA
notBefore=Jul 19 13:50:56 2017 GMT
notAfter=Jul 19 23:59:59 2018 GMT
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Client Authentication, TLS Web Server Authentication
X509v3 Basic Constraints:
CA:FALSE
X509v3 Subject Alternative Name:
DNS:dc1-s-xblm001.adm.example.net, DNS:dc1-s-xblb001.adm.example.net, DNS:scb.example.net
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (4096 bit)
======================================================================
Organisation CA, IPMI web certificate of node A (mgmt zone)
======================================================================
subject=C=<COUNTRY>, O=Example Org, OU=example.net, OU=<RA UNIT>, CN=dc1-a-ablb001m.mgmt.example.net, L=Site 1, emailAddress=admin02@example.net
issuer=C=<COUNTRY>, O=<CA OPERATOR>, OU=<CA OPERATOR UNIT>, CN=Internal CA
notBefore=Jan 8 08:18:03 2018 GMT
notAfter=Jan 8 23:59:59 2019 GMT
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Client Authentication, TLS Web Server Authentication
X509v3 Basic Constraints:
CA:FALSE
X509v3 Subject Alternative Name:
DNS:dc1-a-ablb001m.mgmt.example.net
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
Organisation CA, IPMI web certificate of node B (mgmt zone)
======================================================================
subject=C=<COUNTRY>, O=Example Org, OU=example.net, OU=<RA UNIT>, CN=dc1-b-ablb001m.mgmt.example.net, L=Site 1, emailAddress=admin02@example.net
issuer=C=<COUNTRY>, O=<CA OPERATOR>, OU=<CA OPERATOR UNIT>, CN=Internal CA
notBefore=Jan 8 08:17:01 2018 GMT
notAfter=Jan 8 23:59:59 2019 GMT
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Client Authentication, TLS Web Server Authentication
X509v3 Basic Constraints:
CA:FALSE
X509v3 Subject Alternative Name:
DNS:dc1-b-ablb001m.mgmt.example.net
Signature Algorithm: sha256WithRSAEncryption
Public-Key: (2048 bit)
======================================================================
Organisation root CA certificate kept beside them
======================================================================
subject=C=<COUNTRY>, O=<ROOT CA OPERATOR>, OU=<ROOT CA UNIT>, CN=Internal Root CA 1
issuer=C=<COUNTRY>, O=<ROOT CA OPERATOR>, OU=<ROOT CA UNIT>, CN=Internal Root CA 1
notBefore=Nov 15 12:28:30 2007 GMT
notAfter=Nov 15 23:59:59 2027 GMT
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:1
Signature Algorithm: sha1WithRSAEncryption
Public-Key: (2048 bit)| Block | What it shows |
|---|---|
| SCB internal CA, site 1 | made by the SCB itself on 9 August 2017, valid 20 years less five days. The common names say dc1-s-xblm001, the cluster's management name of the design's DNS records; chapter 7 of the design prints dc1-s-xblb001 on the same page |
| Server certificate, site 1 | the address 10.11.16.81 is in the alternative names twice, once as IP Address: and once as DNS:; the name dc1-s-xblb001… and the user-access name scb.example.net are not in it |
| TSA certificate | Time Stamping as a critical extended key usage, the certificate the organisation's CA could not issue |
| SCB internal CA, site 2 | the same three certificates with L=Site 2 and the site 2 cluster's name, made on 6 March 2018 |
| XCA signing certificate, site 2 | stored as SIGN-cert.pem under _SCB_CA; unlike the site 1 ones it carries admin02's e-mail address, CA:FALSE and a key usage, so, as I read it, it was made from another XCA template |
SCB-AUDIT-SIGN, SCB-AUDIT-ENCRYPT, site 1 | self-signed, ten years, no extensions printed; the dates match the expiry dates in the design |
SCB-AUDIT-ENCRYPT-admin01 | the only per-auditor certificate in the folder, made on 22 May 2018, nine months after the shared ones |
| Organisation CA, cluster web certificate | RSA 4096, one year, client and server authentication, three DNS names; issued three weeks before the SCB made its own CA |
| Organisation CA, IPMI certificates | RSA 2048, one year from 8 January 2018 |
| Organisation root CA | Internal Root CA 1, 2007 to 2027, pathlen:1, signed with SHA-1 |
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| CA, server and TSA certificates generated on the SCB | still possible; the vendor now recommends certificates from your own PKI, because certificates generated on the appliance cannot be revoked |
Server and TSA certificate from one CA; TSA with critical Time Stamping | both rules unchanged; new is the rule that the TSA key usage be non-repudiation and digital signature only (the inventory does not print the key usage of the SCB's TSA certificates) |
| Audit-trail signing certificates without an extended key usage | SPS 9.0 requires the signing certificate's extended key usage to be "Sign (downloadable) executable code" |
| RSA 2048 and SHA-256 for every TLS certificate; root CA signed with SHA-1 | since 6.10.0 an upgrade is blocked by RSA keys under 2048 bits and by SHA-1 or MD5 signatures on certificates other than root CAs; nothing in this inventory falls under that |
Of these certificates, the audit-trail signing certificates are the ones that would have to be made again for SPS 9.0.