Balabit - First server and TSA CSRs
Balabit SCB Solution · Config document · referenced from Certificates and keys
<COUNTRY>, <STATE> and <CITY> are placeholders; "the integrator" and "Example Org" stand for the real organisation names; <MODULUS: …> and <SIGNATURE: …> mark binary parts of the output that are left out.The first round of certificate requests in my working notes, which are headed "BALABIT notes - 4.0.7.a": a server CSR for dc1-a-ablb001.adm.example.net with four names and four addresses as alternative names, and a TSA CSR for the same name, both meant for the organisation's CA. Before them the notes keep two fragments without a command.
| Item | Value |
|---|---|
| Run as | root, in /root/balabit on a RHEL host that the notes do not name |
| SCB firmware at the time | the notes are headed 4.0.7.a |
| Configuration | openssl-balabit.cnf, the RHEL openssl.cnf with the changes shown below; the complete later state is openssl-balabit.cnf |
| Keys | RSA 4096, written unencrypted (genrsa without a cipher option, -nodes) |
| Server CSR | common name dc1-a-ablb001.adm.example.net, alternative names for .81, .89, .65 and .73 |
| TSA CSR | the same subject, extensions from [ tsa_cert ] |
| Result | no certificate; the design's constraint C3 records that the organisation's CA cannot issue TSA certificates |
The commands
The first fragment is a list of subject fields in the shape of the SCB's own certificate form (my reading; the notes give it no heading), with the integrator as the organisation and a common name that was never finished.
output 6 lines
Country=<COUNTRY> Locality name= Organization name=the integrator Organization Unit name= State or province name= Common name=dc1-a-
The second is an OpenSSL req dialogue whose command was not kept, for the name dc1-a-ablm001m1.adm.example.net. It is the only req dialogue in the notes with the integrator as the organisation and with a state and a city.
output 7 lines
Country Name (2 letter code) [XX]:<COUNTRY> State or Province Name (full name) []:<STATE> Locality Name (eg, city) [Default City]:<CITY> Organization Name (eg, company) [Default Company Ltd]:the integrator Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []:dc1-a-ablm001m1.adm.example.net Email Address []:
Prepare the configuration: as root on the RHEL host, copy the system file into a working directory and edit it.
$ cd /root/balabit $ cp /etc/pki/tls/openssl.cnf ./ $ mv ./openssl.cnf ./openssl-balabit.cnf $ vi ./openssl-balabit.cnf
The notes keep the edited parts of the file between two marker lines; ... stands for the unchanged parts.
output 28 lines
... [req] req_extensions = v3_req [ usr_cert] ... extendedKeyUsage = critical,timeStamping [ v3_req ] basicConstraints = CA:FALSE keyUsage = nonRepudiation, digitalSignature, keyEncipherment subjectAltName = @alt_names [alt_names] DNS.1 = dc1-a-ablm001m1.adm.example.net DNS.2 = 10.11.16.81 DNS.3 = dc1-a-ablm001m2.adm.example.net DNS.4 = 10.11.16.89 DNS.5 = scb1.example.net DNS.6 = 10.11.16.65 DNS.7 = scb2.example.net DNS.8 = 10.11.16.73 [ tsa_cert ] extendedKeyUsage = critical,timeStamping ...
Generate the private key of the server certificate. Same host and user.
$ openssl genrsa -out dc1-a-ablb001-4096.key 4096
Generate the server CSR with the edited configuration. The answers typed into the dialogue follow.
$ openssl req -new -out dc1-a-ablb001-4096.csr -key dc1-a-ablb001-4096.key -config openssl-balabit.cnfoutput 12 lines
Country Name (2 letter code) [XX]:<COUNTRY> State or Province Name (full name) []: Locality Name (eg, city) [Default City]:Site 1 Organization Name (eg, company) [Default Company Ltd]:Example Org Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []:dc1-a-ablb001.adm.example.net Email Address []:admin02@example.net Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []:
Check the alternative names in the request.
$ openssl req -text -noout -in dc1-a-ablb001-4096.csr
output 20 lines
Certificate Request:
Data:
Version: 0 (0x0)
Subject: C=<COUNTRY>, L=Site 1, O=Example Org, CN=dc1-a-ablb001.adm.example.net/emailAddress=admin02@example.net
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (4096 bit)
Modulus:
<MODULUS: 512 bytes, not reproduced>
Exponent: 65537 (0x10001)
Attributes:
Requested Extensions:
X509v3 Basic Constraints:
CA:FALSE
X509v3 Key Usage:
Digital Signature, Non Repudiation, Key Encipherment
X509v3 Subject Alternative Name:
DNS:dc1-a-ablm001m1.adm.example.net, IP Address:10.11.16.81, DNS:dc1-a-ablm001m2.adm.example.net, IP Address:10.11.16.89, DNS:scb1.example.net, IP Address:10.11.16.65, DNS:scb2.example.net, IP Address:10.11.16.73
Signature Algorithm: sha256WithRSAEncryption
<SIGNATURE: 512 bytes, not reproduced>Generate the TSA CSR in one command, with a new unencrypted key and the [ tsa_cert ] extensions in place of [ v3_req ].
$ openssl req -set_serial 0 -config openssl-balabit.cnf -reqexts tsa_cert -new -newkey rsa:4096 -keyout dc1-a-ablb001-timestamp.key -out dc1-a-ablb001-timestamp.csr -nodes
output 12 lines
Country Name (2 letter code) [XX]:<COUNTRY> State or Province Name (full name) []: Locality Name (eg, city) [Default City]:Site 1 Organization Name (eg, company) [Default Company Ltd]:Example Org Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []:dc1-a-ablb001.adm.example.net Email Address []:admin02@example.net Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []:
The notes end the round with two checks that have no output: a returned certificate in a file certificate.cer, and the server CSR once more.
$ openssl x509 -in certificate.cer -text -noout $ openssl req -text -noout -in dc1-a-ablb001-4096.csr
| Line | What it means |
|---|---|
Country=… to Common name=dc1-a- | the six fields match the subject fields of the SCB's SSL certificate page (country, locality, organization, organization unit, state or province) plus a common name; the page in the design has the same fields, see SSL certificate (site 1) |
DNS.2 = 10.11.16.81 … DNS.8 = 10.11.16.73 | the excerpt writes the addresses as DNS.n; the -text output shows them as IP Address:, which needs IP.n lines like those of the first copy of openssl-balabit.cnf. As I read it, the excerpt was typed, not copied |
.81, .89, .65, .73 | the management and production addresses of the primary and the NAT-ed secondary networks of the earlier variant, see Hardware, cabling and networks |
scb1.example.net, scb2.example.net | one user-access name per production network of that variant; the final design has one, scb.example.net |
extendedKeyUsage = critical,timeStamping under [ usr_cert] | used only when the file signs certificates itself; see the note in openssl-balabit.cnf |
-set_serial 0 | sets the serial number of a self-signed certificate made with -x509; with a CSR it has no effect (general OpenSSL knowledge) |
-reqexts tsa_cert | takes the request extensions from [ tsa_cert ] in place of req_extensions = v3_req, so the TSA CSR asks for extendedKeyUsage = critical,timeStamping and no alternative names (general OpenSSL behaviour; the notes have no -text of this request) |
admin02@example.net | the e-mail address of admin02, in every CSR of the notes |
Checked against OpenSSL 3.5
| As built | Today |
|---|---|
openssl req … -nodes | -nodes is deprecated since OpenSSL 3.0; -noenc does the same |
-set_serial 0 on a request | the option only sets the serial number of a self-signed certificate; RFC 5280 requires a positive serial, so 0 would be wrong even there |
-reqexts tsa_cert with a copied configuration | still valid; -addext adds an extension directly and overrides one of the same type from the configuration |
addresses as DNS.n in the excerpt | addresses belong in IP.n entries (RFC 5280, RFC 9525), as the -text output of this round shows they were |
| TSA request for a CA | One Identity Safeguard for Privileged Sessions 9.0 still requires the server and the TSA certificate from the same CA, and now also a TSA key usage of non-repudiation and digital signature only |
The options used are all still documented for OpenSSL 3.5; -nodes is marked deprecated.