LINUXOR.SK ... open source notes ...

Balabit - IPMI certificate CSRs

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from IPMI out-of-band management and Certificates and keys

note<COUNTRY> is a placeholder and "Example Org" stands for the organisation.

The how-to I kept beside the certificates of the two IPMI modules: one RSA 2048 key and one CSR per node for the module's name in the out-of-band zone, dc1-a-ablb001m.mgmt.example.net and dc1-b-ablb001m.mgmt.example.net. No -config is given, so OpenSSL took the system's openssl.cnf and the requests carry no alternative names.

ItemValue
Run asroot, on a RHEL host; the how-to does not name it
Configurationthe default openssl.cnf of the host
Keysdc1-a-ablb001m-2048.key, dc1-b-ablb001m-2048.key, RSA 2048, unencrypted
Requestsdc1-a-ablb001m-2048.csr, dc1-b-ablb001m-2048.csr
Certificates that matchissued by the organisation's "Internal CA" on 8 January 2018, valid to 8 January 2019, with the common name as the only alternative name, see the certificate inventory
Meant forthe web interface of each IPMI module, see IPMI out-of-band management
Sourcethe how-to in my certificate folder

The commands

Generate the key and the CSR of node A's IPMI module, as root on the RHEL host. The answers follow the second command.

bash
$ openssl genrsa -out dc1-a-ablb001m-2048.key 2048
$ openssl req -new -out dc1-a-ablb001m-2048.csr -key dc1-a-ablb001m-2048.key
output 11 lines
Country Name (2 letter code) [XX]:<COUNTRY>
State or Province Name (full name) []:
Locality Name (eg, city) [Default City]:Site 1
Organization Name (eg, company) [Default Company Ltd]:Example Org
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:dc1-a-ablb001m.mgmt.example.net
Email Address []:admin02@example.net
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

The same for node B.

bash
$ openssl genrsa -out dc1-b-ablb001m-2048.key 2048
$ openssl req -new -out dc1-b-ablb001m-2048.csr -key dc1-b-ablb001m-2048.key
output 11 lines
Country Name (2 letter code) [XX]:<COUNTRY>
State or Province Name (full name) []:
Locality Name (eg, city) [Default City]:Site 1
Organization Name (eg, company) [Default Company Ltd]:Example Org
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:dc1-b-ablb001m.mgmt.example.net
Email Address []:admin02@example.net
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
LineWhat it means
genrsa … 2048the earlier requests in my notes used 4096-bit keys; these two use 2048, and so do the two IPMI certificates in the inventory. The how-to does not say why
dc1-a-ablb001m.mgmt.example.netthe IPMI host name of chapter 7 of the design and of the network sheets. The design's DNS records and the per-node rounds of my notes use the older name dc1-a-ablm001.mgmt.example.net
no -configthe system file was used, so no alternative names were requested; as I read it, the CA added the common name as the SAN

The design records the IPMI certificates of both nodes as valid from 19 July 2017 to 20 July 2018. The certificates in the folder are, as far as names, key size and dates show, the ones from these requests, valid from 8 January 2018. The documents give neither the reason for the renewal half a year before the old certificates expired nor the names in the old certificates.

← solutionz