Balabit - SSH settings and authentication policy (site 1)
Balabit SCB Solution · Config document · referenced from Connection and channel policies
noteThese algorithm lists still offer
diffie-hellman-group1-sha1, CBC ciphers and hmac-sha1. The site 2 cluster, nine months later, no longer did (see the table at the end). Do not take the lists below as a template.The SSH protocol settings of the site 1 cluster (PARTNER1_SSH and ORG_SSH, identical but for the name), the authentication policy base used by every SSH connection, and the SSH global options.
| Item | Value |
|---|---|
| Where | SCB web interface, SSH Control > Settings, SSH Control > Authentication Policies, SSH Control > Global Options |
| Cluster | dc1-s-xblb001 |
| Firmware at the time | 5 LTS (5.0.3) |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapters 7.6.3 to 7.6.5 |
| Not in it | The idle timeout of the SSH settings (the site 2 file shows 600 s), the built-in default settings |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.6.3 to 7.6.5 SSH Control > Settings > PARTNER1_SSH / NAME = PARTNER1_SSH SSH Control > Settings > PARTNER1_SSH / GREETING = SSH Control > Settings > PARTNER1_SSH / BANNER = ************************************************************************************** / THIS IS A PRIVATE COMPUTER SYSTEM. It is for authorized use only. / Users (authorized or unauthorized) have no explicit or implicit / expectation of privacy. Any or all uses of this system and all files / on this system maybe intercepted, monitored, recorded, copied, / audited, inspected, and disclosed to authorized site and law / enforcement personnel, as well as authorized officials of other / agencies, both domestic and foreign. By using this system, the user / consents to such interception, monitoring, recording, copying, / auditing, inspection, and disclosure at the discretion of authorized / site personnel. Unauthorized or improper use of this system may / result in administrative disciplinary action and civil and criminal / penalties. / By continuing to use this system you indicate your awareness of and / consent to these terms and conditions of use. / LOG OFF IMMEDIATELY if you do not agree to the conditions stated in / this warning. / ************************************************************************************** SSH Control > Settings > PARTNER1_SSH / SOFTWARE VERSION = SSH SSH Control > Settings > PARTNER1_SSH / STRICT MODE = No SSH Control > Settings > PARTNER1_SSH / ALGORITHM SETTINGS = N/A SSH Control > Settings > PARTNER1_SSH / KEX algorithms = Client: diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 / Server: diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 SSH Control > Settings > PARTNER1_SSH / Cipher algorithms = Client: aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,aes192-cbc,aes256-cbc / Server: aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,aes192-cbc,aes256-cbc SSH Control > Settings > PARTNER1_SSH / MAC algorithms = Client: hmac-sha2-256,hmac-sha2-512,hmac-sha1 / Server: hmac-sha2-256,hmac-sha2-512,hmac-sha1 SSH Control > Settings > PARTNER1_SSH / Compression algorithms = Client: none / Server: none SSH Control > Settings > PARTNER1_SSH / ENABLE PRE CHANNEL CHECK = No SSH Control > Settings > ORG_SSH / NAME = ORG_SSH SSH Control > Settings > ORG_SSH / GREETING = SSH Control > Settings > ORG_SSH / BANNER = ************************************************************************************** / THIS IS A PRIVATE COMPUTER SYSTEM. It is for authorized use only. / Users (authorized or unauthorized) have no explicit or implicit / expectation of privacy. Any or all uses of this system and all files / on this system maybe intercepted, monitored, recorded, copied, / audited, inspected, and disclosed to authorized site and law / enforcement personnel, as well as authorized officials of other / agencies, both domestic and foreign. By using this system, the user / consents to such interception, monitoring, recording, copying, / auditing, inspection, and disclosure at the discretion of authorized / site personnel. Unauthorized or improper use of this system may / result in administrative disciplinary action and civil and criminal / penalties. / By continuing to use this system you indicate your awareness of and / consent to these terms and conditions of use. / LOG OFF IMMEDIATELY if you do not agree to the conditions stated in / this warning. / ************************************************************************************** SSH Control > Settings > ORG_SSH / SOFTWARE VERSION = SSH SSH Control > Settings > ORG_SSH / STRICT MODE = No SSH Control > Settings > ORG_SSH / ALGORITHM SETTINGS = N/A SSH Control > Settings > ORG_SSH / KEX algorithms = Client: diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 / Server: diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 SSH Control > Settings > ORG_SSH / Cipher algorithms = Client: aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,aes192-cbc,aes256-cbc / Server: aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,aes192-cbc,aes256-cbc SSH Control > Settings > ORG_SSH / MAC algorithms = Client: hmac-sha2-256,hmac-sha2-512,hmac-sha1 / Server: hmac-sha2-256,hmac-sha2-512,hmac-sha1 SSH Control > Settings > ORG_SSH / Compression algorithms = Client: none / Server: none SSH Control > Settings > ORG_SSH / ENABLE PRE CHANNEL CHECK = No SSH Control > Authentication Policies > base / CLIENT-SIDE GATEWAY AUTHENTICATION BACKEND = NONE SSH Control > Authentication Policies > base / GSSAPI-BASED SINGLE SIGN-ON = No SSH Control > Authentication Policies > base / RELAYED AUTHENTICATION METHODS / PASSWORD / KEYBOARD-INTERACTIVE / PUBLIC KEY / X.509 CERTIFICATE = VALUES / Yes / Yes / No / No SSH Control > Global Options > TRAFFIC / SERVICE = enabled SSH Control > Global Options > TRAFFIC / VERBOSITY LEVEL = 4 SSH Control > Global Options > AUDIT / TIMESTAMPING = Local SSH Control > Global Options > AUDIT / TIMESTAMPING POLICY = SSH Control > Global Options > AUDIT / SIGNING INTERVAL = 30 (s) SSH Control > Global Options > AUDIT / CHANNEL DATABASE CLEANUP = 180 (days) SSH Control > Global Options > GSSAPI / KERBEROS KEYTAB FILE = SSH Control > Global Options > GSSAPI / DOMAIN TO REALM MAPPING =
| Field | What it means |
|---|---|
| BANNER | Shown to the client before authentication. Each / is a line break of the original |
| SOFTWARE VERSION = SSH | As I understand it, the software version the SCB announces in its own SSH version string |
| STRICT MODE = No | As I understand it, strict mode makes the SCB reject protocol messages that do not follow the RFCs strictly; it was off |
| KEX, Cipher, MAC, Compression algorithms | The lists offered on the client side and on the server side. Compression off |
| ENABLE PRE CHANNEL CHECK = No | As I understand it, with the pre channel check the SCB evaluates the channel policy before it opens the connection to the server |
| CLIENT-SIDE GATEWAY AUTHENTICATION BACKEND = NONE | The user does not authenticate to the SCB itself; the SCB relays the authentication to the jump server |
| RELAYED AUTHENTICATION METHODS | Password and keyboard-interactive yes, public key and X.509 no. Users cannot log in with SSH keys through the SCB |
| TIMESTAMPING = Local, SIGNING INTERVAL = 30 (s) | Audit trails are timestamped by the SCB's own TSA and signed every 30 seconds, see Audit trails |
| CHANNEL DATABASE CLEANUP = 180 (days) | Connection metadata older than 180 days is deleted from the SCB's database |
| GSSAPI | Kerberos is not used |
The same settings in the site 2 config.xml of 2018-09-17:
| Setting | Site 1 (design, 2017-12) | Site 2 (config.xml, 2018-09) |
|---|---|---|
| KEX | diffie-hellman-group14-sha1, diffie-hellman-group1-sha1 | diffie-hellman-group-exchange-sha256, diffie-hellman-group-exchange-sha1, diffie-hellman-group14-sha1 |
| Ciphers | aes128-ctr, aes192-ctr, aes256-ctr and the three CBC variants | the three CTR variants only |
| MAC | hmac-sha2-256, hmac-sha2-512, hmac-sha1 | hmac-sha2-256, hmac-sha2-512 |
| Pre channel check | No | yes |
| Authentication policy | base | base (built-in id -200): password and keyboard-interactive, no public key |
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
KEX diffie-hellman-group14-sha1, diffie-hellman-group1-sha1 | SPS 9.0 default: ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group-exchange-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group14-sha256. Both as-built algorithms are "Not recommended". OpenSSH disabled diffie-hellman-group1-sha1 by default in 7.0 (2015) and removed diffie-hellman-group14-sha1 from its default proposal in 8.2 (2020) |
| Ciphers with three CBC variants | Default aes128-ctr, aes192-ctr, aes256-ctr, aes128-gcm@openssh.com, aes256-gcm@openssh.com; CBC "Not recommended". The OpenSSH client has not offered CBC by default since 7.6 (2017) |
MACs with hmac-sha1 | Default UMAC and SHA-2, ETM variants first; hmac-sha1 "Not recommended". An ETM MAC now requires strict key exchange from the peer (Terrapin) |
| Compression none | Still the default; zlib is "Not recommended" |
| Customised algorithm lists | An upgrade updates the lists only if they were left at their defaults; these customised lists would stay as they are |
| Relayed password and keyboard-interactive | Unchanged option; the checklist recommends gateway authentication |
The SCB 5 defaults were already stronger than these lists (group-exchange SHA-256 first, CTR only, SHA-2 only, the values site 2 has), and the vendor's checklist of that time already said not to use CBC or diffie-hellman-group1-sha1. Site 1 replaced the defaults with weaker lists; the documents do not say why.