LINUXOR.SK ... open source notes ...

Balabit - Cluster web certificate CSR

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Certificates and keys

note<COUNTRY> is a placeholder and "Example Org" stands for the organisation. The certificate issued from this request is not the one the web interface uses in the design: chapter 7 shows a certificate from the SCB's own CA.

The how-to I kept beside the final certificates, headed "Server certs - DC1-A+B": one key and one CSR for the cluster's management name dc1-s-xblm001.adm.example.net, with dc1-s-xblb001.adm.example.net and scb.example.net as alternative names, made with openssl-balabit.cnf. One certificate serves both nodes, as I understand the HA pair, because the name and the address move with the master.

ItemValue
Run asroot, on a RHEL host, in the directory that holds openssl-balabit.cnf
Keydc1-s-xblm001-4096-adm.key, RSA 4096, unencrypted
Requestdc1-s-xblm001-4096-adm.csr, subject C=<COUNTRY>, L=Site 1, O=Example Org, CN=dc1-s-xblm001.adm.example.net, e-mail admin02@example.net
Alternative names requesteddc1-s-xblb001.adm.example.net, scb.example.net
Certificate that matchesissued by the organisation's "Internal CA", valid 19 July 2017 to 19 July 2018, RSA 4096, alternative names dc1-s-xblm001…, dc1-s-xblb001…, scb.example.net, see the certificate inventory
Sourcethe how-to in my certificate folder

The commands

Switch the alternative names on and set them to the cluster's names, as root on the RHEL host. The excerpt is as the how-to keeps it.

bash
$ vi openssl-balabit.cnf
output 8 lines
[ v3_req ]
...
subjectAltName = @alt_names
...
[alt_names]
DNS.1 = dc1-s-xblb001.adm.example.net
DNS.2 = scb.example.net
...

Generate the private key.

bash
$ openssl genrsa -out dc1-s-xblm001-4096-adm.key 4096

Generate the CSR with the edited configuration; the answers follow.

bash
$ openssl req -new -out dc1-s-xblm001-4096-adm.csr -key dc1-s-xblm001-4096-adm.key -config openssl-balabit.cnf
output 12 lines
Country Name (2 letter code) [XX]:<COUNTRY>
State or Province Name (full name) []:
Locality Name (eg, city) [Default City]:Site 1
Organization Name (eg, company) [Default Company Ltd]:Example Org
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:dc1-s-xblm001.adm.example.net
Email Address []:admin02@example.net

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

Check the alternative names. The how-to keeps no output.

bash
$ openssl req -text -noout -in dc1-s-xblm001-4096-adm.csr
LineWhat it means
subjectAltName = @alt_namesswitched on here, unlike in the per-node rounds
DNS.1 = dc1-s-xblb001.adm.example.netthe cluster's name in chapter 7 and in the later network sheets, for the in-band management address 10.11.16.81; the design's DNS records give the same name to the production address 10.11.16.65
DNS.2 = scb.example.netthe name for user access, which points to the production address
dc1-s-xblm001.adm.example.netthe cluster's management name in the design's DNS records and in the SCB's own certificates
-4096-adm in the file namesthe key size and the adm zone; as I read it, to keep these files apart from the earlier ones and from the mgmt ones of the IPMI modules

The certificate that came back differs from the request in its subject: the CA added OU=example.net and an organisational unit of its own, moved the locality behind the common name and put the common name into the alternative names. It is valid for one year, as the analysis said the organisation's CA issues them.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
Web certificate requested from the organisation's CA, the SCB's internal CA used in the endSPS 9.0 recommends generating certificates with your own PKI and uploading them, because certificates generated on the appliance cannot be revoked; the server and the TSA certificate must still come from the same CA
Common name and two DNS namesthe server certificate's common name must hold the domain name or the IP address of the host, and every address of the web interface must be listed in the alternative names; the extended key usage must be TLS Web Server Authentication, which this certificate has

The vendor's advice today is what this request tried in 2017; the same-CA rule that stopped it is still there.

← solutionz