Balabit - SSL certificate (site 1)
Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring and Certificates and keys
dc1-s-xblb001.adm.example.net, the files of the same three certificates say dc1-s-xblm001.adm.example.net. <COUNTRY> and <KEY_FINGERPRINT> are placeholders, and "Example Org" stands for the organisation.The page that holds the SCB's three own certificates and their private keys: the certificate of its internal CA, the server certificate of the web interface and the certificate of its time-stamping authority (TSA), all three generated on the appliance by its internal CA, and the subject fields the appliance used for them.
| Item | Value |
|---|---|
| Where | Basic Settings > Management > SSL certificate |
| Cluster | dc1-s-xblb001, site 1 |
| Firmware at the time | 5 LTS (5.0.3) |
| Certificates | CA, server and TSA, RSA 2048, generated on 9 August 2017 and valid to 2037, see the certificate inventory |
| Source | design document v0.5 of 2017-12-01, chapter 7.2.15 |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.2.15 Basic Settings > Management > SSL certificate / CA X.509 CERTIFICATE = Subject 1: /C=<COUNTRY>/L=Site 1/O=Example Org/OU=example.net/CN=dc1-s-xblb001.adm.example.net root CA Basic Settings > Management > SSL certificate / CA X.509 CERTIFICATE – PEM file = Basic Settings > Management > SSL certificate / CA PRIVATE KEY = Fingerprint: 2048 SHA256:<KEY_FINGERPRINT> Basic Settings > Management > SSL certificate / CA PRIVATE KEY – PEM file (Public part of the key) = Basic Settings > Management > SSL certificate / SERVER X.509 CERTIFICATE = Subject 1: /C=<COUNTRY>/L=Site 1/O=Example Org/OU=example.net/CN=dc1-s-xblb001.adm.example.net Basic Settings > Management > SSL certificate / SERVER X.509 CERTIFICATE – PEM file = Basic Settings > Management > SSL certificate / SERVER PRIVATE KEY = Fingerprint: 2048 SHA256:<KEY_FINGERPRINT> Basic Settings > Management > SSL certificate / SERVER PRIVATE KEY - PEM file (Public part of the key) = Basic Settings > Management > SSL certificate / TSA X.509 CERTIFICATE = Subject 1: /C=<COUNTRY>/L=Site 1/O=Example Org/OU=example.net/CN=dc1-s-xblb001.adm.example.net Time Stamping Authority Basic Settings > Management > SSL certificate / TSA X.509 CERTIFICATE – PEM file = Basic Settings > Management > SSL certificate / TSA PRIVATE KEY = Fingerprint: 2048 SHA256:<KEY_FINGERPRINT> Basic Settings > Management > SSL certificate / TSA PRIVATE KEY – PEM file (Public part of the key) = Basic Settings > Management > SSL certificate / COUNTRY = <COUNTRY> Basic Settings > Management > SSL certificate / LOCALITY NAME = Site 1 Basic Settings > Management > SSL certificate / ORGANIZATION NAME = Example Org Basic Settings > Management > SSL certificate / ORGANIZATION UNIT NAME = example.net Basic Settings > Management > SSL certificate / STATE OR PROVINCE NAME =
| Field | What it means |
|---|---|
CA X.509 CERTIFICATE | the root of the SCB's internal CA. It signed the server and the TSA certificate below; an auditor's player needs it to trust the timestamps of an audit trail, see Audit trails: encryption and replay |
SERVER X.509 CERTIFICATE | the certificate of the web interface on 10.11.16.81. Its alternative names are the address and dc1-s-xblm001.adm.example.net |
TSA X.509 CERTIFICATE | the key with which the SCB timestamps audit trails itself ("Local" timestamping in the global options of each protocol) |
… PEM file | empty in the design: the table records the subjects and fingerprints, not the files |
COUNTRY to STATE OR PROVINCE NAME | the subject fields the appliance used when it generated the three certificates; they are the parameters of the CA in chapter 4.10.1 of the design |
The design explains why these three certificates come from the SCB's own CA: the organisation's CA could not issue a TSA certificate, and the server and the TSA certificate had to come from the same CA (constraint C3 and chapter 4.1.7). The site 2 cluster's config.xml holds the same three pairs as ssl_certificate/ssl_private_key, ca_cert/ca_key and tsa_cert/tsa_key in its management settings; the export replaced the certificates by placeholders and the keys by [removed sensitive data].
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| CA, server and TSA certificates generated on the SCB | still how SPS starts, but the vendor recommends uploading certificates from your own PKI; certificates generated on the appliance cannot be revoked |
| Server and TSA from the same CA | unchanged ("The Server and the TSA certificates must be issued by the same Certificate Authority") |
TSA certificate with critical Time Stamping | unchanged, plus a key usage of non-repudiation and digital signature only |
| Server certificate naming one address | every address of the web interface must be in the alternative names, and the common name must hold the host's domain name or address |
| RSA 2048, SHA-256 | above the limits that block an upgrade since 6.10.0 (RSA under 2048 bits, SHA-1 or MD5 signatures) |
The page and its rules are the same today; the vendor's advice changed from generating on the box to bringing your own CA, which is what C3 ruled out in 2017.