Balabit - System (site 1)
Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring and Operations, upgrades and troubleshooting
<LICENSE_SERIAL> replaces the serial number of the licence. The licence of the site 2 cluster, exported nine months later, describes a different licence model; see below.The System section of Basic Settings at the time the design document was written: which firmware the cluster ran, which licence it had, and whether sealed mode was on.
| Item | Value |
|---|---|
| Where | SCB web interface, Basic Settings > System |
| Cluster | dc1-s-xblb001, site 1 |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapters 7.2.21 to 7.2.23 |
| Compared with | The <license> and <features> elements of the site 2 config.xml of 2018-09-17, and the site 2 support bundle of the same day |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.2.21 to 7.2.23 Basic Settings > System > Version details / CORE FIRMWARE = 5 LTS (5.0.3) Basic Settings > System > Version details / BOOT FIRMWARE = 5.0.3-5.0.3 Basic Settings > System > Version details / BUILD DATE = 2017-11-11T21:50:23+00:00 Basic Settings > System > License / CUSTOMER = the integrator Basic Settings > System > License / SERIAL = <LICENSE_SERIAL> Basic Settings > System > License / LIMIT TYPE = Host Basic Settings > System > License / HOST LIMIT = 1000 Basic Settings > System > License / VALID = Not defined Basic Settings > System > Sealed mode / ACTIVATE SEALED MODE = Disabled
| Setting | What it means here |
|---|---|
| Core 5 LTS (5.0.3), boot 5.0.3-5.0.3 | The appliance runs two firmwares: the boot firmware starts the box and handles high availability, the core firmware does everything else. Both were at 5.0.3, built on 2017-11-11. My working notes are headed "BALABIT notes - 4.0.7.a", which, as I read it, means the appliances started on version 4; the troubleshooting notes fix a web server "after upgrade from version 4 to version 5". The upgrade is told in Operations, upgrades and troubleshooting |
| Limit type Host, 1000 | A host-based licence: chapter 6.5 of the design explains that the appliance counts the IP addresses of the protected hosts, and that jump servers and the servers reached from them all count |
| Valid "Not defined" | No expiry date was shown |
| Sealed mode Disabled | Sealed mode was not used; the design gives no reason |
The site 2 cluster tells a different story about the licence. Its config.xml carries Edition: T10 (Connection based), Limit: 20, Session-Based-License: yes, Date: 2017/07/18 and the licensed options core, ssh-proxy, audit-trail, basic-proxies, Highavailability. A host limit of 1000 and a session limit of 20 are not the same licence, and my material does not say whether site 1 kept the host-based one. The same file holds <seal_the_box>yes</seal_the_box> in its <features> element; whether that means sealed mode was active in site 2 or only that the feature was available, the file does not say. In September 2018 the site 2 cluster ran core and boot firmware 5.0.6.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| Balabit Shell Control Box 5 LTS, 5.0.3 | One Identity acquired Balabit in January 2018; the product is One Identity Safeguard for Privileged Sessions (SPS). 5.0.x LTS reached Limited Support on 2019-05-28 and was discontinued on 2020-05-28. The current documents are SPS 9.0 (September 2026) and 8.0.2.1 LTS |
| T-10 appliance | The T-Series was last sold on 2019-06-30 and reached End of Support on 2024-07-31; SPS 8.0 is not supported on T-Series hardware. 9.0 installs on generic hardware or certified Dell and HPE servers |
| Upgrade within 5.0.x | From 5 LTS to 9.0 every LTS has to be passed: the latest 5.0.x, then 6.0 LTS, 7.0 LTS, 8.0 LTS, then 9.0; downgrades are not possible |
| Host-based licence, 1000 hosts | 8.0.2.1 LTS required a new licence. 9.0 needs no licence file at all, and the Basic Settings > System > License page has been removed |
| Sealed mode disabled | Sealed mode still exists and can be switched on in the Welcome Wizard or later |
None of this page survives as it was: the product, the hardware and the licence model have all changed. SPS 8.0 and later are not supported on a T-10 pair; the way forward is a new deployment and the documented data migration from one SPS instance to another.