LINUXOR.SK ... open source notes ...

Balabit - First server and TSA CSRs

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Certificates and keys

noteA dead end: no certificate from this round is in the certificate folder, by constraint C3 the organisation's CA could not issue TSA certificates, and the alternative names belong to an earlier network variant. <COUNTRY>, <STATE> and <CITY> are placeholders; "the integrator" and "Example Org" stand for the real organisation names; <MODULUS: …> and <SIGNATURE: …> mark binary parts of the output that are left out.

The first round of certificate requests in my working notes, which are headed "BALABIT notes - 4.0.7.a": a server CSR for dc1-a-ablb001.adm.example.net with four names and four addresses as alternative names, and a TSA CSR for the same name, both meant for the organisation's CA. Before them the notes keep two fragments without a command.

ItemValue
Run asroot, in /root/balabit on a RHEL host that the notes do not name
SCB firmware at the timethe notes are headed 4.0.7.a
Configurationopenssl-balabit.cnf, the RHEL openssl.cnf with the changes shown below; the complete later state is openssl-balabit.cnf
KeysRSA 4096, written unencrypted (genrsa without a cipher option, -nodes)
Server CSRcommon name dc1-a-ablb001.adm.example.net, alternative names for .81, .89, .65 and .73
TSA CSRthe same subject, extensions from [ tsa_cert ]
Resultno certificate; the design's constraint C3 records that the organisation's CA cannot issue TSA certificates

The commands

The first fragment is a list of subject fields in the shape of the SCB's own certificate form (my reading; the notes give it no heading), with the integrator as the organisation and a common name that was never finished.

output 6 lines
Country=<COUNTRY>
Locality name=
Organization name=the integrator
Organization Unit name=
State or province name=
Common name=dc1-a-

The second is an OpenSSL req dialogue whose command was not kept, for the name dc1-a-ablm001m1.adm.example.net. It is the only req dialogue in the notes with the integrator as the organisation and with a state and a city.

output 7 lines
Country Name (2 letter code) [XX]:<COUNTRY>
State or Province Name (full name) []:<STATE>
Locality Name (eg, city) [Default City]:<CITY>
Organization Name (eg, company) [Default Company Ltd]:the integrator
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:dc1-a-ablm001m1.adm.example.net
Email Address []:

Prepare the configuration: as root on the RHEL host, copy the system file into a working directory and edit it.

bash
$ cd /root/balabit
$ cp /etc/pki/tls/openssl.cnf ./
$ mv ./openssl.cnf ./openssl-balabit.cnf
$ vi ./openssl-balabit.cnf

The notes keep the edited parts of the file between two marker lines; ... stands for the unchanged parts.

output 28 lines
...

[req]
req_extensions = v3_req

[ usr_cert]
...
extendedKeyUsage = critical,timeStamping

[ v3_req ]
basicConstraints = CA:FALSE
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
subjectAltName = @alt_names

[alt_names]
DNS.1 = dc1-a-ablm001m1.adm.example.net
DNS.2 = 10.11.16.81
DNS.3 = dc1-a-ablm001m2.adm.example.net
DNS.4 = 10.11.16.89
DNS.5 = scb1.example.net
DNS.6 = 10.11.16.65
DNS.7 = scb2.example.net
DNS.8 = 10.11.16.73

[ tsa_cert ]
extendedKeyUsage = critical,timeStamping

...

Generate the private key of the server certificate. Same host and user.

bash
$ openssl genrsa -out dc1-a-ablb001-4096.key 4096

Generate the server CSR with the edited configuration. The answers typed into the dialogue follow.

bash
$ openssl req -new -out dc1-a-ablb001-4096.csr -key dc1-a-ablb001-4096.key -config openssl-balabit.cnf
output 12 lines
Country Name (2 letter code) [XX]:<COUNTRY>
State or Province Name (full name) []:
Locality Name (eg, city) [Default City]:Site 1
Organization Name (eg, company) [Default Company Ltd]:Example Org
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:dc1-a-ablb001.adm.example.net
Email Address []:admin02@example.net

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

Check the alternative names in the request.

bash
$ openssl req -text -noout -in dc1-a-ablb001-4096.csr
output 20 lines
Certificate Request:
    Data:
        Version: 0 (0x0)
        Subject: C=<COUNTRY>, L=Site 1, O=Example Org, CN=dc1-a-ablb001.adm.example.net/emailAddress=admin02@example.net
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (4096 bit)
                Modulus:
                    <MODULUS: 512 bytes, not reproduced>
                Exponent: 65537 (0x10001)
        Attributes:
        Requested Extensions:
            X509v3 Basic Constraints:
                CA:FALSE
            X509v3 Key Usage:
                Digital Signature, Non Repudiation, Key Encipherment
            X509v3 Subject Alternative Name:
                DNS:dc1-a-ablm001m1.adm.example.net, IP Address:10.11.16.81, DNS:dc1-a-ablm001m2.adm.example.net, IP Address:10.11.16.89, DNS:scb1.example.net, IP Address:10.11.16.65, DNS:scb2.example.net, IP Address:10.11.16.73
    Signature Algorithm: sha256WithRSAEncryption
         <SIGNATURE: 512 bytes, not reproduced>

Generate the TSA CSR in one command, with a new unencrypted key and the [ tsa_cert ] extensions in place of [ v3_req ].

bash
$ openssl req -set_serial 0 -config openssl-balabit.cnf -reqexts tsa_cert -new -newkey rsa:4096 -keyout dc1-a-ablb001-timestamp.key -out dc1-a-ablb001-timestamp.csr -nodes
output 12 lines
Country Name (2 letter code) [XX]:<COUNTRY>
State or Province Name (full name) []:
Locality Name (eg, city) [Default City]:Site 1
Organization Name (eg, company) [Default Company Ltd]:Example Org
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:dc1-a-ablb001.adm.example.net
Email Address []:admin02@example.net

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

The notes end the round with two checks that have no output: a returned certificate in a file certificate.cer, and the server CSR once more.

bash
$ openssl x509 -in certificate.cer -text -noout
$ openssl req -text -noout -in dc1-a-ablb001-4096.csr
LineWhat it means
Country=… to Common name=dc1-a-the six fields match the subject fields of the SCB's SSL certificate page (country, locality, organization, organization unit, state or province) plus a common name; the page in the design has the same fields, see SSL certificate (site 1)
DNS.2 = 10.11.16.81 … DNS.8 = 10.11.16.73the excerpt writes the addresses as DNS.n; the -text output shows them as IP Address:, which needs IP.n lines like those of the first copy of openssl-balabit.cnf. As I read it, the excerpt was typed, not copied
.81, .89, .65, .73the management and production addresses of the primary and the NAT-ed secondary networks of the earlier variant, see Hardware, cabling and networks
scb1.example.net, scb2.example.netone user-access name per production network of that variant; the final design has one, scb.example.net
extendedKeyUsage = critical,timeStamping under [ usr_cert]used only when the file signs certificates itself; see the note in openssl-balabit.cnf
-set_serial 0sets the serial number of a self-signed certificate made with -x509; with a CSR it has no effect (general OpenSSL knowledge)
-reqexts tsa_certtakes the request extensions from [ tsa_cert ] in place of req_extensions = v3_req, so the TSA CSR asks for extendedKeyUsage = critical,timeStamping and no alternative names (general OpenSSL behaviour; the notes have no -text of this request)
admin02@example.netthe e-mail address of admin02, in every CSR of the notes

Checked against OpenSSL 3.5

As builtToday
openssl req … -nodes-nodes is deprecated since OpenSSL 3.0; -noenc does the same
-set_serial 0 on a requestthe option only sets the serial number of a self-signed certificate; RFC 5280 requires a positive serial, so 0 would be wrong even there
-reqexts tsa_cert with a copied configurationstill valid; -addext adds an extension directly and overrides one of the same type from the configuration
addresses as DNS.n in the excerptaddresses belong in IP.n entries (RFC 5280, RFC 9525), as the -text output of this round shows they were
TSA request for a CAOne Identity Safeguard for Privileged Sessions 9.0 still requires the server and the TSA certificate from the same CA, and now also a TSA key usage of non-repudiation and digital signature only

The options used are all still documented for OpenSSL 3.5; -nodes is marked deprecated.

← solutionz