Balabit - SSH connections (site 1)
Balabit SCB Solution · Config document · referenced from Connection and channel policies
<SSH_HOST_KEY> is a placeholder for the SCB's public RSA host key. The two SCP/SFTP connections reference the channel policies PARTNER1-SSH-ONLY and ORG-SSH-ONLY, which as documented allow only a shell and X11; the documented SCP/SFTP channel policies are not referenced by any connection. The site 2 configuration assigns the SCP/SFTP policies to these connections, so the site 1 table is probably a copy slip, but I cannot prove what site 1 really ran.The four SSH connection policies of the site 1 cluster as recorded in December 2017: shell and file transfer, for partner 1 and for the organisation. The two shell connections lead to a Linux jump server in the management LAN and to the IPv6 ranges of the out-of-band jump servers in sites 1 to 5; the two file transfer connections lead to the shared file server.
| Item | Value |
|---|---|
| Where | SCB web interface, SSH Control > Connections |
| Cluster | dc1-s-xblb001, production address 10.11.16.65 and 2001:db8:a1:c0e::f:1 |
| Firmware at the time | 5 LTS (5.0.3) |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapter 7.6.1 |
| Not in it | The later connections of partner 3 (2205, 2206) and of the cloud team of partner 1 (2210, 2211), only in the connection summary |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.6.1 SSH Control > Connections > PARTNER1_SSH_JumpServer > BASIC SETTINGS / ENABLED = Yes SSH Control > Connections > PARTNER1_SSH_JumpServer > BASIC SETTINGS / NAME = PARTNER1_SSH_JumpServer SSH Control > Connections > PARTNER1_SSH_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0 SSH Control > Connections > PARTNER1_SSH_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128 SSH Control > Connections > PARTNER1_SSH_JumpServer > BASIC SETTINGS / PORT = 22 SSH Control > Connections > PARTNER1_SSH_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.17.81 (22) / 2001:db8:a1:f94::/64 (22) / 2001:db8:b1:f94::/64 (22) / 2001:db8:a2:f94::/64 (22) / 2001:db8:10de:f94::/64 (22) / 2001:db8:215e:f94::/64 (22) / 2001:db8:21de:f94::/64 (22) / 2001:db8:315e:f94::/64 (22) / 2001:db8:31de:f94::/64 (22) / 2001:db8:325e:f94::/64 (22) / 2001:db8:32de:f94::/64 (22) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A SSH Control > Connections > PARTNER1_SSH_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes SSH Control > Connections > PARTNER1_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes SSH Control > Connections > PARTNER1_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / PLAIN HOST KEY CHECK = Accept key for the first time SSH Control > Connections > PARTNER1_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No SSH Control > Connections > PARTNER1_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes SSH Control > Connections > PARTNER1_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / RSA HOST KEY = ssh-rsa <SSH_HOST_KEY> SSH Control > Connections > PARTNER1_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / DSA HOST KEY = SSH Control > Connections > PARTNER1_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / SSH SETTINGS = PARTNER1_SSH SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / CHANNEL POLICY = PARTNER1-SSH-ONLY SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / BACKUP POLICY = PARTNER1-BACKUP SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / AUTHENTICATION POLICY = base SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / AUDIT POLICY = default SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = PARTNER1-ARCHIVE SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / AA PLUGIN = SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes SSH Control > Connections > ORG_SSH_JumpServer > BASIC SETTINGS / ENABLED = Yes SSH Control > Connections > ORG_SSH_JumpServer > BASIC SETTINGS / NAME = ORG_SSH_JumpServer SSH Control > Connections > ORG_SSH_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0 SSH Control > Connections > ORG_SSH_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128 SSH Control > Connections > ORG_SSH_JumpServer > BASIC SETTINGS / PORT = 2201 SSH Control > Connections > ORG_SSH_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.16.177 (22) / 2001:db8:a1:f95::/64 (22) / 2001:db8:b1:f95::/64 (22) / 2001:db8:a2:f95::/64 (22) / 2001:db8:10de:f95::/64 (22) / 2001:db8:215e:f95::/64 (22) / 2001:db8:21de:f95::/64 (22) / 2001:db8:315e:f95::/64 (22) / 2001:db8:31de:f95::/64 (22) / 2001:db8:325e:f95::/64 (22) / 2001:db8:32de:f95::/64 (22) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A SSH Control > Connections > ORG_SSH_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes SSH Control > Connections > ORG_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes SSH Control > Connections > ORG_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / PLAIN HOST KEY CHECK = Accept key for the first time SSH Control > Connections > ORG_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No SSH Control > Connections > ORG_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes SSH Control > Connections > ORG_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / RSA HOST KEY = ssh-rsa <SSH_HOST_KEY> SSH Control > Connections > ORG_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / DSA HOST KEY = SSH Control > Connections > ORG_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / SSH SETTINGS = ORG_SSH SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / CHANNEL POLICY = ORG-SSH-ONLY SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / BACKUP POLICY = ORG-BACKUP SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / AUTHENTICATION POLICY = base SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / AUDIT POLICY = default SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = ORG-ARCHIVE SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / AA PLUGIN = SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > BASIC SETTINGS / ENABLED = Yes SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > BASIC SETTINGS / NAME = PARTNER1_SCP_SFTP_JumpServer SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0 SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128 SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > BASIC SETTINGS / PORT = 222 SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.17.129 (22) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / PLAIN HOST KEY CHECK = Accept key for the first time SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / RSA HOST KEY = ssh-rsa <SSH_HOST_KEY> SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / DSA HOST KEY = SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / SSH SETTINGS = PARTNER1_SSH SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / CHANNEL POLICY = PARTNER1-SSH-ONLY SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / BACKUP POLICY = PARTNER1-BACKUP SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / AUTHENTICATION POLICY = base SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / AUDIT POLICY = default SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = PARTNER1-ARCHIVE SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / AA PLUGIN = SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes SSH Control > Connections > ORG_SCP_SFTP_JumpServer > BASIC SETTINGS / ENABLED = Yes SSH Control > Connections > ORG_SCP_SFTP_JumpServer > BASIC SETTINGS / NAME = ORG_SCP_SFTP_JumpServer SSH Control > Connections > ORG_SCP_SFTP_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0 SSH Control > Connections > ORG_SCP_SFTP_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128 SSH Control > Connections > ORG_SCP_SFTP_JumpServer > BASIC SETTINGS / PORT = 2203 SSH Control > Connections > ORG_SCP_SFTP_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.17.129 (22) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A SSH Control > Connections > ORG_SCP_SFTP_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes SSH Control > Connections > ORG_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes SSH Control > Connections > ORG_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / PLAIN HOST KEY CHECK = Accept key for the first time SSH Control > Connections > ORG_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No SSH Control > Connections > ORG_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes SSH Control > Connections > ORG_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / RSA HOST KEY = ssh-rsa <SSH_HOST_KEY> SSH Control > Connections > ORG_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / DSA HOST KEY = SSH Control > Connections > ORG_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / SSH SETTINGS = ORG_SSH SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / CHANNEL POLICY = ORG-SSH-ONLY SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / BACKUP POLICY = ORG-BACKUP SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / AUTHENTICATION POLICY = base SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / AUDIT POLICY = default SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = ORG-ARCHIVE SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / AA PLUGIN = SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes
| Field | What it means |
|---|---|
| INBAND DESTINATION SELECTION | 10.11.17.81 (dc1-a-vcjmp002) or 10.11.16.177 (dc1-a-vcjmp001) in the management LAN, plus one /64 per out-of-band location; 10.11.17.129 (dc1-a-vcscp001) for file transfer. Every target listens on port 22 |
| SERVER SIDE HOSTKEY SETTINGS | How the SCB checks the jump server's key: plain keys allowed, the first key seen is stored and later checked against, no X.509 host certificates |
| CLIENT SIDE HOSTKEY SETTINGS | What the SCB shows the client: its own RSA host key; no DSA key, no X.509 |
| SSH SETTINGS | PARTNER1_SSH or ORG_SSH: SSH settings |
| AUTHENTICATION POLICY = base | Password and keyboard-interactive, relayed to the jump server; no public key |
| CHANNEL POLICY | See the note above and channel policies |
| Other fields | As for RDP: RDP connections |
The SCP/SFTP connection of partner 1 listens on 222 and that of the organisation on 2203, while the design's OpenSSH scp examples for the organisation use port 2201, the port of the SSH connection; the end-user side is in End-user access.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| ALLOW X.509 HOST CERTIFICATES = No | For SSH, X.509 host certificates are no longer supported; the options have been removed |
| DSA HOST KEY empty | DSA keys are no longer supported for SSH; RSA or Ed25519 are recommended |
RSA HOST KEY ssh-rsa | Still in the default host key list, but marked "Not recommended" because it depends on SHA-1 and "will be disabled in a future release" |
| PLAIN HOST KEY CHECK = Accept key for the first time | The checklist asks to "ensure that host key verification is enabled in SSH connection policies" |
IPv6 /64 targets | Unchanged: IPv6 ranges are given as prefixes |
| AUTHENTICATION POLICY = base, GATEWAY AUTHENTICATION = No | Relayed password and keyboard-interactive remain; the checklist still says "Always use gateway authentication to authenticate clients" |
Two options of this page, X.509 host certificates and the DSA host key, are gone from the product, and the RSA host key the SCB presents is on its way out.