Balabit - Cluster web certificate CSR
Balabit SCB Solution · Config document · referenced from Certificates and keys
<COUNTRY> is a placeholder and "Example Org" stands for the organisation. The certificate issued from this request is not the one the web interface uses in the design: chapter 7 shows a certificate from the SCB's own CA.The how-to I kept beside the final certificates, headed "Server certs - DC1-A+B": one key and one CSR for the cluster's management name dc1-s-xblm001.adm.example.net, with dc1-s-xblb001.adm.example.net and scb.example.net as alternative names, made with openssl-balabit.cnf. One certificate serves both nodes, as I understand the HA pair, because the name and the address move with the master.
| Item | Value |
|---|---|
| Run as | root, on a RHEL host, in the directory that holds openssl-balabit.cnf |
| Key | dc1-s-xblm001-4096-adm.key, RSA 4096, unencrypted |
| Request | dc1-s-xblm001-4096-adm.csr, subject C=<COUNTRY>, L=Site 1, O=Example Org, CN=dc1-s-xblm001.adm.example.net, e-mail admin02@example.net |
| Alternative names requested | dc1-s-xblb001.adm.example.net, scb.example.net |
| Certificate that matches | issued by the organisation's "Internal CA", valid 19 July 2017 to 19 July 2018, RSA 4096, alternative names dc1-s-xblm001…, dc1-s-xblb001…, scb.example.net, see the certificate inventory |
| Source | the how-to in my certificate folder |
The commands
Switch the alternative names on and set them to the cluster's names, as root on the RHEL host. The excerpt is as the how-to keeps it.
$ vi openssl-balabit.cnfoutput 8 lines
[ v3_req ] ... subjectAltName = @alt_names ... [alt_names] DNS.1 = dc1-s-xblb001.adm.example.net DNS.2 = scb.example.net ...
Generate the private key.
$ openssl genrsa -out dc1-s-xblm001-4096-adm.key 4096
Generate the CSR with the edited configuration; the answers follow.
$ openssl req -new -out dc1-s-xblm001-4096-adm.csr -key dc1-s-xblm001-4096-adm.key -config openssl-balabit.cnfoutput 12 lines
Country Name (2 letter code) [XX]:<COUNTRY> State or Province Name (full name) []: Locality Name (eg, city) [Default City]:Site 1 Organization Name (eg, company) [Default Company Ltd]:Example Org Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []:dc1-s-xblm001.adm.example.net Email Address []:admin02@example.net Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []:
Check the alternative names. The how-to keeps no output.
$ openssl req -text -noout -in dc1-s-xblm001-4096-adm.csr
| Line | What it means |
|---|---|
subjectAltName = @alt_names | switched on here, unlike in the per-node rounds |
DNS.1 = dc1-s-xblb001.adm.example.net | the cluster's name in chapter 7 and in the later network sheets, for the in-band management address 10.11.16.81; the design's DNS records give the same name to the production address 10.11.16.65 |
DNS.2 = scb.example.net | the name for user access, which points to the production address |
dc1-s-xblm001.adm.example.net | the cluster's management name in the design's DNS records and in the SCB's own certificates |
-4096-adm in the file names | the key size and the adm zone; as I read it, to keep these files apart from the earlier ones and from the mgmt ones of the IPMI modules |
The certificate that came back differs from the request in its subject: the CA added OU=example.net and an organisational unit of its own, moved the locality behind the common name and put the common name into the alternative names. It is valid for one year, as the analysis said the organisation's CA issues them.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| Web certificate requested from the organisation's CA, the SCB's internal CA used in the end | SPS 9.0 recommends generating certificates with your own PKI and uploading them, because certificates generated on the appliance cannot be revoked; the server and the TSA certificate must still come from the same CA |
| Common name and two DNS names | the server certificate's common name must hold the domain name or the IP address of the host, and every address of the web interface must be listed in the alternative names; the extended key usage must be TLS Web Server Authentication, which this certificate has |
The vendor's advice today is what this request tried in 2017; the same-CA rule that stopped it is still there.