Balabit - IPMI of node A (site 1)
Balabit SCB Solution · Config document · referenced from IPMI out-of-band management
<LOCAL_UTC_OFFSET> is a placeholder for the time zone, and password_for_scb_mail was a placeholder already in my design document; neither is a value to copy. The page "LDAP" says No while the page "Active Directory" lists two role groups; the design does not show whether Active Directory authentication itself was switched on, see the table below.Every page of the IPMI web interface (the SuperMicro BMC) of the SCB appliance in datacenter A as I recorded it in the design document: alerts, time, directory, network, SMTP, certificate, users, ports. The design says that it shows only what was changed from the defaults.
| Item | Value |
|---|---|
| Where | IPMI web interface of node A, https://dc1-a-ablb001m.mgmt.example.net/, 10.11.15.29 |
| Appliance | dc1-a-ablb001, SCB T-10 in datacenter A, node of the site 1 cluster dc1-s-xblb001 |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapter 7.1.1, "configuration from real implementation realized in production environment" |
| Node B | The same except Alerts, Network and SSL Certification: IPMI of node B |
| Not in it | The firmware version of the BMC, the Active Directory switch itself, the Configure > Users password (changed, not recorded) |
The answers
# Page / Field = value, as configured on dc1-a-ablb001 (IPMI), from the design document v0.5, chapter 7.1.1 Alerts > Alert 1 / Alert Level = Warning and Above Alerts > Alert 1 / Destination Address = 010.011.019.033 & scb_mail_group@ad.example.net Alerts > Alert 2 … 16 / Alert Level = Disable All Alerts > Alert 2 … 16 / Destination Address = 000.000.000.000 & NULL Alerts > Alert 1 (detail) / Event Severity = Warning Alerts > Alert 1 (detail) / Destination IP = 010.011.019.033 Alerts > Alert 1 (detail) / Email Address = scb_mail_group@ad.example.net Alerts > Alert 1 (detail) / Subject = dc1-a-ablm001 - Alert Alerts > Alert 1 (detail) / Message = NULL Date & Time / TIME ZONE = <LOCAL_UTC_OFFSET> Date & Time / NTP ENABLE = Enable Date & Time / PRIMARY NTP SERVER = 10.11.16.145 Date & Time / SECONDARY NTP SERVER = 10.11.18.145 Date & Time / DAYLIGHT SAVING TIME = No LDAP / ENABLE LDAP AUTHENTICATION = No Active Directory > Role Group 1 / Group Name = SCB_ADM_ORG Active Directory > Role Group 1 / Group Domain = ad.example.net Active Directory > Role Group 1 / Network Privilege = Administrator Active Directory > Role Group 2 / Group Name = SCB_OPS_ORG Active Directory > Role Group 2 / Group Domain = ad.example.net Active Directory > Role Group 2 / Network Privilege = Operator Active Directory > Role Group 3 … 5 / Group Name = ~ Active Directory > Role Group 3 … 5 / Group Domain = ~ Active Directory > Role Group 3 … 5 / Network Privilege = Reserverd Active Directory > Role Group 1 (detail) / ROLE GROUP NAME = SCB_ADM_ORG Active Directory > Role Group 1 (detail) / ROLE GROUP DOMAIN = ad.example.net Active Directory > Role Group 1 (detail) / ROLE GROUP PRIVILEGE = Administrator Active Directory > Role Group 2 (detail) / ROLE GROUP NAME = SCB_OPS_ORG Active Directory > Role Group 2 (detail) / ROLE GROUP DOMAIN = ad.example.net Active Directory > Role Group 2 (detail) / ROLE GROUP PRIVILEGE = Operator RADIUS / ENABLE RADIUS = No Mouse mode / MOUSE MODE = Set Mode to Absolute (Windows, Ubuntu, RH6.x later) Network > BASIC SETTINGS / MAC ADDRESS = 0c-c4-7a-00-00-01 Network > BASIC SETTINGS / HOSTNAME = dc1-a-ablb001m.mgmt.example.net Network > BASIC SETTINGS / USE THE FOLLOWING IP ADDRESS = Yes Network > IPv4 SETTINGS / IP ADDRESS = 010.011.015.029 Network > IPv4 SETTINGS / SUBNET MASK = 255.255.255.000 Network > IPv4 SETTINGS / GATEWAY = 10.11.15.254 Network > IPv4 SETTINGS / DNS = 10.11.16.145 Network > IPv6 SETTINGS / DHCPv6 STATELESS = Yes Network > IPv6 SETTINGS / ADDRESS LIST = 2001:db8:a1:0ff3:0016:0000:00e7:0001/64 Network > IPv6 SETTINGS / DNS SERVER IP = 2001:db8:a1:c0b::f:1 Network > OTHER SETTINGS / VLAN = Disabled Network > OTHER SETTINGS / VLAN ID = 0 Network > OTHER SETTINGS / LAN INTERFACE = Dedicate Network > OTHER SETTINGS / RMCP PORT = 623 Dynamic DNS / DYNAMIC UPDATE DISABLE = Yes Dynamic DNS / ENABLE TSIG AUTHENTICATION = No Remote session / VIRTUAL MEDIA ATTACH MODE = Auto Attach SMTP / SMTP SSL AUTH = Yes SMTP / SMTP SERVER = 10.11.19.33 SMTP / SMTP PORT NUMBER = 25 SMTP / SMTP USER NAME = scb_mail@ad.example.net SMTP / SMTP PASSWORD = password_for_scb_mail SMTP / SENDER’S ADDRESS = scb_mail@ad.example.net SSL Certification / Signed by = internal certification authority SSL Certification / Valid from = 7/19/2017 SSL Certification / Valid to = 7/20/2018 Users > User 1 / User Name = Anonymous Users > User 1 / Network Privilege = Reserved Users > User 2 / User Name = ADMIN Users > User 2 / Network Privilege = Administrator Users > User 3 … 10 / User Name = ~ Users > User 3 … 10 / Network Privilege = Reserved Port > WEB PORT / Enabled = No Port > WEB PORT / Value = 80 Port > WEB SSL PORT / Enabled = Yes Port > WEB SSL PORT / Value = 443 Port > IKVM SERVER PORT / Enabled = Yes Port > IKVM SERVER PORT / Value = 5900 Port > VIRTUAL MEDIA PORT / Enabled = No Port > VIRTUAL MEDIA PORT / Value = 623 Port > SSH PORT / Enabled = No Port > SSH PORT / Value = 22 Port > WSMAN PORT / Enabled = No Port > WSMAN PORT / Value = 5985 IP Access Control / ENABLE IP ACCESS CONTROL = No Fan mode / FAN MODE = Set Fan to Standard Speed
The SSL Certification page is a sentence in the design, not a table: the certificate "is signed by internal certification authority", was uploaded with its private key, and it is valid "from 7/19/2017 to 7/20/2018". The field names Signed by, Valid from and Valid to are mine.
| Answer | What it means |
|---|---|
Destination IP 010.011.019.033 | The SMTP virtual address 10.11.19.33 of the mail pair (see Network, DNS and firewall), written with leading zeros the way the BMC page shows it. IP ADDRESS 010.011.015.029 is 10.11.15.29 written the same way |
Subject dc1-a-ablm001 - Alert | The older name of the IPMI module; the HOSTNAME on the Network page already uses the newer dc1-a-ablb001m |
Role groups SCB_ADM_ORG, SCB_OPS_ORG | The same Active Directory groups that give administrator and operator rights on the SCB web interface. On the SuperMicro BMC, as I know it, Active Directory authentication has its own switch on the Active Directory page; the design lists the role groups but not that switch, and the LDAP switch is No |
VLAN Disabled | The BMC sends untagged frames; the switch port is an access port in VLAN 12 |
LAN INTERFACE Dedicate | The BMC uses its own IPMI port and not a shared LAN port; set with ipmitool raw 0x30 0x70 0xc 1 0, see the ipmitool commands |
SMTP PORT NUMBER 25 with SMTP SSL AUTH Yes | The design's table of out-of-band communications opens TCP 465 (SMTPS) from the IPMI modules to 10.11.19.33, not 25. Which of the two was right is not recorded |
| Ports | Only HTTPS (443) and the iKVM console (5900) are on; plain HTTP, SSH, virtual media and WS-Management are off |
TIME ZONE <LOCAL_UTC_OFFSET>, DAYLIGHT SAVING TIME No | The BMC keeps a fixed UTC offset without daylight saving; the design gives no reason |
Valid to 7/20/2018 | The IPMI certificates in my certificate folder are newer: issued by the organisation's CA, valid from 2018-01-08 to 2019-01-08, see Certificates and keys |
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| IPMI in the out-of-band network, reachable from "Any" on 443 and 5900 | The SPS 9.0 guide: the IPMI "has known vulnerabilities that One Identity cannot fix"; connect it "only … to well-protected, separated management networks with restricted accessibility" |
| VIRTUAL MEDIA PORT 623 off | Matches SuperMicro's interim mitigation for CVE-2019-16649 and CVE-2019-16650 (plaintext authentication, weak encryption and authentication bypass in Virtual Media on X9 to H12 boards): block TCP port 623 and run BMCs on isolated networks. Whether a firmware fix exists for the X9 board was not confirmed |
| SSH PORT 22 off | Still the right choice: even the BMC of the current 3000/3500 appliances offers 3des-cbc, diffie-hellman-group1-sha1, hmac-md5 and ssh-dss on its SSH port |
| The ports on the Port page | The 9.0 guide lists the same IPMI ports and adds 161 (SNMP): 22, 80, 161, 443, 623, 5900, 5985 |
The appliance under this module is out of support (T-Series End of Support 2024-07-31), so no BMC firmware updates should be expected for it either; that is my conclusion, not a statement of the research.