LINUXOR.SK ... open source notes ...

Balabit - SSL certificate (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring and Certificates and keys

noteThe subjects on this page do not match the certificate files: the page prints the common name dc1-s-xblb001.adm.example.net, the files of the same three certificates say dc1-s-xblm001.adm.example.net. <COUNTRY> and <KEY_FINGERPRINT> are placeholders, and "Example Org" stands for the organisation.

The page that holds the SCB's three own certificates and their private keys: the certificate of its internal CA, the server certificate of the web interface and the certificate of its time-stamping authority (TSA), all three generated on the appliance by its internal CA, and the subject fields the appliance used for them.

ItemValue
WhereBasic Settings > Management > SSL certificate
Clusterdc1-s-xblb001, site 1
Firmware at the time5 LTS (5.0.3)
CertificatesCA, server and TSA, RSA 2048, generated on 9 August 2017 and valid to 2037, see the certificate inventory
Sourcedesign document v0.5 of 2017-12-01, chapter 7.2.15

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.2.15
Basic Settings > Management > SSL certificate / CA X.509 CERTIFICATE = Subject 1: /C=<COUNTRY>/L=Site 1/O=Example Org/OU=example.net/CN=dc1-s-xblb001.adm.example.net root CA
Basic Settings > Management > SSL certificate / CA X.509 CERTIFICATE – PEM file = 
Basic Settings > Management > SSL certificate / CA PRIVATE KEY = Fingerprint: 2048 SHA256:<KEY_FINGERPRINT>
Basic Settings > Management > SSL certificate / CA PRIVATE KEY – PEM file (Public part of the key) = 
Basic Settings > Management > SSL certificate / SERVER X.509 CERTIFICATE = Subject 1: /C=<COUNTRY>/L=Site 1/O=Example Org/OU=example.net/CN=dc1-s-xblb001.adm.example.net
Basic Settings > Management > SSL certificate / SERVER X.509 CERTIFICATE – PEM file = 
Basic Settings > Management > SSL certificate / SERVER PRIVATE KEY = Fingerprint: 2048 SHA256:<KEY_FINGERPRINT>
Basic Settings > Management > SSL certificate / SERVER PRIVATE KEY - PEM file (Public part of the key) = 
Basic Settings > Management > SSL certificate / TSA X.509 CERTIFICATE = Subject 1: /C=<COUNTRY>/L=Site 1/O=Example Org/OU=example.net/CN=dc1-s-xblb001.adm.example.net Time Stamping Authority
Basic Settings > Management > SSL certificate / TSA X.509 CERTIFICATE – PEM file = 
Basic Settings > Management > SSL certificate / TSA PRIVATE KEY = Fingerprint: 2048 SHA256:<KEY_FINGERPRINT>
Basic Settings > Management > SSL certificate / TSA PRIVATE KEY – PEM file (Public part of the key) = 
Basic Settings > Management > SSL certificate / COUNTRY = <COUNTRY>
Basic Settings > Management > SSL certificate / LOCALITY NAME = Site 1
Basic Settings > Management > SSL certificate / ORGANIZATION NAME = Example Org
Basic Settings > Management > SSL certificate / ORGANIZATION UNIT NAME = example.net
Basic Settings > Management > SSL certificate / STATE OR PROVINCE NAME = 
FieldWhat it means
CA X.509 CERTIFICATEthe root of the SCB's internal CA. It signed the server and the TSA certificate below; an auditor's player needs it to trust the timestamps of an audit trail, see Audit trails: encryption and replay
SERVER X.509 CERTIFICATEthe certificate of the web interface on 10.11.16.81. Its alternative names are the address and dc1-s-xblm001.adm.example.net
TSA X.509 CERTIFICATEthe key with which the SCB timestamps audit trails itself ("Local" timestamping in the global options of each protocol)
… PEM fileempty in the design: the table records the subjects and fingerprints, not the files
COUNTRY to STATE OR PROVINCE NAMEthe subject fields the appliance used when it generated the three certificates; they are the parameters of the CA in chapter 4.10.1 of the design

The design explains why these three certificates come from the SCB's own CA: the organisation's CA could not issue a TSA certificate, and the server and the TSA certificate had to come from the same CA (constraint C3 and chapter 4.1.7). The site 2 cluster's config.xml holds the same three pairs as ssl_certificate/ssl_private_key, ca_cert/ca_key and tsa_cert/tsa_key in its management settings; the export replaced the certificates by placeholders and the keys by [removed sensitive data].

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
CA, server and TSA certificates generated on the SCBstill how SPS starts, but the vendor recommends uploading certificates from your own PKI; certificates generated on the appliance cannot be revoked
Server and TSA from the same CAunchanged ("The Server and the TSA certificates must be issued by the same Certificate Authority")
TSA certificate with critical Time Stampingunchanged, plus a key usage of non-repudiation and digital signature only
Server certificate naming one addressevery address of the web interface must be in the alternative names, and the common name must hold the host's domain name or address
RSA 2048, SHA-256above the limits that block an upgrade since 6.10.0 (RSA under 2048 bits, SHA-1 or MD5 signatures)

The page and its rules are the same today; the vendor's advice changed from generating on the box to bringing your own CA, which is what C3 ruled out in 2017.

← solutionz