LINUXOR.SK ... open source notes ...

Balabit - SSH connections (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Connection and channel policies

note<SSH_HOST_KEY> is a placeholder for the SCB's public RSA host key. The two SCP/SFTP connections reference the channel policies PARTNER1-SSH-ONLY and ORG-SSH-ONLY, which as documented allow only a shell and X11; the documented SCP/SFTP channel policies are not referenced by any connection. The site 2 configuration assigns the SCP/SFTP policies to these connections, so the site 1 table is probably a copy slip, but I cannot prove what site 1 really ran.

The four SSH connection policies of the site 1 cluster as recorded in December 2017: shell and file transfer, for partner 1 and for the organisation. The two shell connections lead to a Linux jump server in the management LAN and to the IPv6 ranges of the out-of-band jump servers in sites 1 to 5; the two file transfer connections lead to the shared file server.

ItemValue
WhereSCB web interface, SSH Control > Connections
Clusterdc1-s-xblb001, production address 10.11.16.65 and 2001:db8:a1:c0e::f:1
Firmware at the time5 LTS (5.0.3)
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapter 7.6.1
Not in itThe later connections of partner 3 (2205, 2206) and of the cloud team of partner 1 (2210, 2211), only in the connection summary

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.6.1

SSH Control > Connections > PARTNER1_SSH_JumpServer > BASIC SETTINGS / ENABLED = Yes
SSH Control > Connections > PARTNER1_SSH_JumpServer > BASIC SETTINGS / NAME = PARTNER1_SSH_JumpServer
SSH Control > Connections > PARTNER1_SSH_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0
SSH Control > Connections > PARTNER1_SSH_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128
SSH Control > Connections > PARTNER1_SSH_JumpServer > BASIC SETTINGS / PORT = 22
SSH Control > Connections > PARTNER1_SSH_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.17.81 (22) / 2001:db8:a1:f94::/64 (22) / 2001:db8:b1:f94::/64 (22) / 2001:db8:a2:f94::/64 (22) / 2001:db8:10de:f94::/64 (22) / 2001:db8:215e:f94::/64 (22) / 2001:db8:21de:f94::/64 (22) / 2001:db8:315e:f94::/64 (22) / 2001:db8:31de:f94::/64 (22) / 2001:db8:325e:f94::/64 (22) / 2001:db8:32de:f94::/64 (22) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A
SSH Control > Connections > PARTNER1_SSH_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes
SSH Control > Connections > PARTNER1_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes
SSH Control > Connections > PARTNER1_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / PLAIN HOST KEY CHECK = Accept key for the first time
SSH Control > Connections > PARTNER1_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No
SSH Control > Connections > PARTNER1_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes
SSH Control > Connections > PARTNER1_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / RSA HOST KEY = ssh-rsa <SSH_HOST_KEY>
SSH Control > Connections > PARTNER1_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / DSA HOST KEY = 
SSH Control > Connections > PARTNER1_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = 
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = 
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / SSH SETTINGS = PARTNER1_SSH
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / CHANNEL POLICY = PARTNER1-SSH-ONLY
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / BACKUP POLICY = PARTNER1-BACKUP
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = 
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / AUTHENTICATION POLICY = base
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / AUDIT POLICY = default
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = 
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = PARTNER1-ARCHIVE
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / AA PLUGIN = 
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No
SSH Control > Connections > PARTNER1_SSH_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes

SSH Control > Connections > ORG_SSH_JumpServer > BASIC SETTINGS / ENABLED = Yes
SSH Control > Connections > ORG_SSH_JumpServer > BASIC SETTINGS / NAME = ORG_SSH_JumpServer
SSH Control > Connections > ORG_SSH_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0
SSH Control > Connections > ORG_SSH_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128
SSH Control > Connections > ORG_SSH_JumpServer > BASIC SETTINGS / PORT = 2201
SSH Control > Connections > ORG_SSH_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.16.177 (22) / 2001:db8:a1:f95::/64 (22) / 2001:db8:b1:f95::/64 (22) / 2001:db8:a2:f95::/64 (22) / 2001:db8:10de:f95::/64 (22) / 2001:db8:215e:f95::/64 (22) / 2001:db8:21de:f95::/64 (22) / 2001:db8:315e:f95::/64 (22) / 2001:db8:31de:f95::/64 (22) / 2001:db8:325e:f95::/64 (22) / 2001:db8:32de:f95::/64 (22) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A
SSH Control > Connections > ORG_SSH_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes
SSH Control > Connections > ORG_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes
SSH Control > Connections > ORG_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / PLAIN HOST KEY CHECK = Accept key for the first time
SSH Control > Connections > ORG_SSH_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No
SSH Control > Connections > ORG_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes
SSH Control > Connections > ORG_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / RSA HOST KEY = ssh-rsa <SSH_HOST_KEY>
SSH Control > Connections > ORG_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / DSA HOST KEY = 
SSH Control > Connections > ORG_SSH_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = 
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = 
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / SSH SETTINGS = ORG_SSH
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / CHANNEL POLICY = ORG-SSH-ONLY
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / BACKUP POLICY = ORG-BACKUP
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = 
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / AUTHENTICATION POLICY = base
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / AUDIT POLICY = default
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = 
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = ORG-ARCHIVE
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / AA PLUGIN = 
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No
SSH Control > Connections > ORG_SSH_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes

SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > BASIC SETTINGS / ENABLED = Yes
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > BASIC SETTINGS / NAME = PARTNER1_SCP_SFTP_JumpServer
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > BASIC SETTINGS / PORT = 222
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.17.129 (22) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / PLAIN HOST KEY CHECK = Accept key for the first time
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / RSA HOST KEY = ssh-rsa <SSH_HOST_KEY>
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / DSA HOST KEY = 
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = 
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = 
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / SSH SETTINGS = PARTNER1_SSH
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / CHANNEL POLICY = PARTNER1-SSH-ONLY
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / BACKUP POLICY = PARTNER1-BACKUP
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = 
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / AUTHENTICATION POLICY = base
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / AUDIT POLICY = default
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = 
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = PARTNER1-ARCHIVE
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / AA PLUGIN = 
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No
SSH Control > Connections > PARTNER1_SCP_SFTP_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes

SSH Control > Connections > ORG_SCP_SFTP_JumpServer > BASIC SETTINGS / ENABLED = Yes
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > BASIC SETTINGS / NAME = ORG_SCP_SFTP_JumpServer
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > BASIC SETTINGS / PORT = 2203
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.17.129 (22) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / PLAIN HOST KEY CHECK = Accept key for the first time
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > SERVER SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW PLAIN HOST KEYS = Yes
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / RSA HOST KEY = ssh-rsa <SSH_HOST_KEY>
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / DSA HOST KEY = 
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > CLIENT SIDE HOSTKEY SETTINGS / ALLOW X.509 HOST CERTIFICATES = No
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = 
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = 
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / SSH SETTINGS = ORG_SSH
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / CHANNEL POLICY = ORG-SSH-ONLY
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / BACKUP POLICY = ORG-BACKUP
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = 
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / AUTHENTICATION POLICY = base
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / AUDIT POLICY = default
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = 
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = ORG-ARCHIVE
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / AA PLUGIN = 
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No
SSH Control > Connections > ORG_SCP_SFTP_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes
FieldWhat it means
INBAND DESTINATION SELECTION10.11.17.81 (dc1-a-vcjmp002) or 10.11.16.177 (dc1-a-vcjmp001) in the management LAN, plus one /64 per out-of-band location; 10.11.17.129 (dc1-a-vcscp001) for file transfer. Every target listens on port 22
SERVER SIDE HOSTKEY SETTINGSHow the SCB checks the jump server's key: plain keys allowed, the first key seen is stored and later checked against, no X.509 host certificates
CLIENT SIDE HOSTKEY SETTINGSWhat the SCB shows the client: its own RSA host key; no DSA key, no X.509
SSH SETTINGSPARTNER1_SSH or ORG_SSH: SSH settings
AUTHENTICATION POLICY = basePassword and keyboard-interactive, relayed to the jump server; no public key
CHANNEL POLICYSee the note above and channel policies
Other fieldsAs for RDP: RDP connections

The SCP/SFTP connection of partner 1 listens on 222 and that of the organisation on 2203, while the design's OpenSSH scp examples for the organisation use port 2201, the port of the SSH connection; the end-user side is in End-user access.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
ALLOW X.509 HOST CERTIFICATES = NoFor SSH, X.509 host certificates are no longer supported; the options have been removed
DSA HOST KEY emptyDSA keys are no longer supported for SSH; RSA or Ed25519 are recommended
RSA HOST KEY ssh-rsaStill in the default host key list, but marked "Not recommended" because it depends on SHA-1 and "will be disabled in a future release"
PLAIN HOST KEY CHECK = Accept key for the first timeThe checklist asks to "ensure that host key verification is enabled in SSH connection policies"
IPv6 /64 targetsUnchanged: IPv6 ranges are given as prefixes
AUTHENTICATION POLICY = base, GATEWAY AUTHENTICATION = NoRelayed password and keyboard-interactive remain; the checklist still says "Always use gateway authentication to authenticate clients"

Two options of this page, X.509 host certificates and the DSA host key, are gone from the product, and the RSA host key the SCB presents is on its way out.

← solutionz