LINUXOR.SK ... open source notes ...

Balabit - Server and OOB CSRs per node

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Certificates and keys

noteTwo mistakes are kept. The two server rounds are headed "switch the alternative DNS names on", but the excerpt under that heading shows #subjectAltName = @alt_names commented out, the same as in the two out-of-band rounds that switch them off. And the out-of-band rounds write the same file names as the server rounds (dc1-a-ablm001-4096.key, dc1-a-ablm001-4096.csr and the same for B) in the same directory, so run in this order they overwrite the server keys and requests. <COUNTRY> is a placeholder and "Example Org" stands for the organisation.

Four rounds of my working notes after the first attempt, all for the organisation's CA: a server CSR per node for its in-band management name (dc1-a-ablm001.adm.example.net, dc1-b-ablm001.adm.example.net) and an out-of-band CSR per node for the name of its IPMI module (dc1-a-ablm001.mgmt.example.net, dc1-b-ablm001.mgmt.example.net), each with a new RSA 4096 key.

ItemValue
Run asroot, presumably in /root/balabit on the same RHEL host as the first attempt; the notes do not say
Configurationopenssl-balabit.cnf, [alt_names] cut down to DNS.1 = scb.example.net
Server CSRsdc1-a-ablm001.adm.example.net, dc1-b-ablm001.adm.example.net
Out-of-band CSRsdc1-a-ablm001.mgmt.example.net, dc1-b-ablm001.mgmt.example.net
KeysRSA 4096, unencrypted
Output keptnone: the -text checks are in the notes without their output
Resultno certificate with these names is in the certificate folder. The design says the IPMI web certificates were issued by the organisation's CA on 19 July 2017; the notes do not say from which requests

The commands

Server certificate, datacenter A

Switch the alternative names on in the configuration, as root on the RHEL host. The excerpt is as the notes keep it.

bash
$ vi openssl-balabit.cnf
output 7 lines
[ v3_req ]
...
#subjectAltName = @alt_names
...
[alt_names]
DNS.1 = scb.example.net
...

Generate the key of node A.

bash
$ openssl genrsa -out dc1-a-ablm001-4096.key 4096

Generate the server CSR of node A with the answers below.

bash
$ openssl req -new -out dc1-a-ablm001-4096.csr -key dc1-a-ablm001-4096.key -config openssl-balabit.cnf
output 12 lines
Country Name (2 letter code) [XX]:<COUNTRY>
State or Province Name (full name) []:
Locality Name (eg, city) [Default City]:Site 1
Organization Name (eg, company) [Default Company Ltd]:Example Org
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:dc1-a-ablm001.adm.example.net
Email Address []:admin02@example.net

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

Check the alternative names. No output is kept.

bash
$ openssl req -text -noout -in dc1-a-ablm001-4096.csr

Server certificate, datacenter B

The same for node B, starting with the same edit.

bash
$ vi openssl-balabit.cnf
output 7 lines
[ v3_req ]
...
#subjectAltName = @alt_names
...
[alt_names]
DNS.1 = scb.example.net
...

Generate the key of node B.

bash
$ openssl genrsa -out dc1-b-ablm001-4096.key 4096

Generate the server CSR of node B.

bash
$ openssl req -new -out dc1-b-ablm001-4096.csr -key dc1-b-ablm001-4096.key -config openssl-balabit.cnf
output 12 lines
Country Name (2 letter code) [XX]:<COUNTRY>
State or Province Name (full name) []:
Locality Name (eg, city) [Default City]:Site 1
Organization Name (eg, company) [Default Company Ltd]:Example Org
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:dc1-b-ablm001.adm.example.net
Email Address []:admin02@example.net

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

Check the alternative names. No output is kept.

bash
$ openssl req -text -noout -in dc1-b-ablm001-4096.csr

Out-of-band certificate, datacenter A

Switch the alternative names off for the IPMI name.

bash
$ vi openssl-balabit.cnf
output 4 lines
[ v3_req ]
...
#subjectAltName = @alt_names
...

Generate a key for the IPMI module of node A, under the file name already used for the server key.

bash
$ openssl genrsa -out dc1-a-ablm001-4096.key 4096

Generate the CSR for the IPMI name of node A.

bash
$ openssl req -new -out dc1-a-ablm001-4096.csr -key dc1-a-ablm001-4096.key -config openssl-balabit.cnf
output 12 lines
Country Name (2 letter code) [XX]:<COUNTRY>
State or Province Name (full name) []:
Locality Name (eg, city) [Default City]:Site 1
Organization Name (eg, company) [Default Company Ltd]:Example Org
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:dc1-a-ablm001.mgmt.example.net
Email Address []:admin02@example.net

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

Check the request. No output is kept.

bash
$ openssl req -text -noout -in dc1-a-ablm001-4096.csr

Out-of-band certificate, datacenter B

The same edit for node B.

bash
$ vi openssl-balabit.cnf
output 4 lines
[ v3_req ]
...
#subjectAltName = @alt_names
...

Generate a key for the IPMI module of node B.

bash
$ openssl genrsa -out dc1-b-ablm001-4096.key 4096

Generate the CSR for the IPMI name of node B.

bash
$ openssl req -new -out dc1-b-ablm001-4096.csr -key dc1-b-ablm001-4096.key -config openssl-balabit.cnf
output 12 lines
Country Name (2 letter code) [XX]:<COUNTRY>
State or Province Name (full name) []:
Locality Name (eg, city) [Default City]:Site 1
Organization Name (eg, company) [Default Company Ltd]:Example Org
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:dc1-b-ablm001.mgmt.example.net
Email Address []:admin02@example.net

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

Check the request. No output is kept.

bash
$ openssl req -text -noout -in dc1-b-ablm001-4096.csr
LineWhat it means
dc1-a-ablm001.adm.example.neta per-node name in the in-band management zone that appears nowhere else in the documents; in the design's DNS records the in-band management address belongs to the cluster only, as dc1-s-xblm001.adm.example.net
dc1-a-ablm001.mgmt.example.netthe IPMI name of node A in the design's DNS records. Chapter 7 of the design and the network sheets name the IPMI module dc1-a-ablb001m.mgmt.example.net, the name of the final IPMI requests
DNS.1 = scb.example.netthe user-access name; with subjectAltName commented out it is not requested at all
admin02@example.netthe e-mail address of admin02, as in every CSR of the notes
← solutionz