Balabit - Server and OOB CSRs per node
Balabit SCB Solution · Config document · referenced from Certificates and keys
#subjectAltName = @alt_names commented out, the same as in the two out-of-band rounds that switch them off. And the out-of-band rounds write the same file names as the server rounds (dc1-a-ablm001-4096.key, dc1-a-ablm001-4096.csr and the same for B) in the same directory, so run in this order they overwrite the server keys and requests. <COUNTRY> is a placeholder and "Example Org" stands for the organisation.Four rounds of my working notes after the first attempt, all for the organisation's CA: a server CSR per node for its in-band management name (dc1-a-ablm001.adm.example.net, dc1-b-ablm001.adm.example.net) and an out-of-band CSR per node for the name of its IPMI module (dc1-a-ablm001.mgmt.example.net, dc1-b-ablm001.mgmt.example.net), each with a new RSA 4096 key.
| Item | Value |
|---|---|
| Run as | root, presumably in /root/balabit on the same RHEL host as the first attempt; the notes do not say |
| Configuration | openssl-balabit.cnf, [alt_names] cut down to DNS.1 = scb.example.net |
| Server CSRs | dc1-a-ablm001.adm.example.net, dc1-b-ablm001.adm.example.net |
| Out-of-band CSRs | dc1-a-ablm001.mgmt.example.net, dc1-b-ablm001.mgmt.example.net |
| Keys | RSA 4096, unencrypted |
| Output kept | none: the -text checks are in the notes without their output |
| Result | no certificate with these names is in the certificate folder. The design says the IPMI web certificates were issued by the organisation's CA on 19 July 2017; the notes do not say from which requests |
The commands
Server certificate, datacenter A
Switch the alternative names on in the configuration, as root on the RHEL host. The excerpt is as the notes keep it.
$ vi openssl-balabit.cnfoutput 7 lines
[ v3_req ] ... #subjectAltName = @alt_names ... [alt_names] DNS.1 = scb.example.net ...
Generate the key of node A.
$ openssl genrsa -out dc1-a-ablm001-4096.key 4096
Generate the server CSR of node A with the answers below.
$ openssl req -new -out dc1-a-ablm001-4096.csr -key dc1-a-ablm001-4096.key -config openssl-balabit.cnfoutput 12 lines
Country Name (2 letter code) [XX]:<COUNTRY> State or Province Name (full name) []: Locality Name (eg, city) [Default City]:Site 1 Organization Name (eg, company) [Default Company Ltd]:Example Org Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []:dc1-a-ablm001.adm.example.net Email Address []:admin02@example.net Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []:
Check the alternative names. No output is kept.
$ openssl req -text -noout -in dc1-a-ablm001-4096.csr
Server certificate, datacenter B
The same for node B, starting with the same edit.
$ vi openssl-balabit.cnfoutput 7 lines
[ v3_req ] ... #subjectAltName = @alt_names ... [alt_names] DNS.1 = scb.example.net ...
Generate the key of node B.
$ openssl genrsa -out dc1-b-ablm001-4096.key 4096
Generate the server CSR of node B.
$ openssl req -new -out dc1-b-ablm001-4096.csr -key dc1-b-ablm001-4096.key -config openssl-balabit.cnfoutput 12 lines
Country Name (2 letter code) [XX]:<COUNTRY> State or Province Name (full name) []: Locality Name (eg, city) [Default City]:Site 1 Organization Name (eg, company) [Default Company Ltd]:Example Org Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []:dc1-b-ablm001.adm.example.net Email Address []:admin02@example.net Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []:
Check the alternative names. No output is kept.
$ openssl req -text -noout -in dc1-b-ablm001-4096.csr
Out-of-band certificate, datacenter A
Switch the alternative names off for the IPMI name.
$ vi openssl-balabit.cnfoutput 4 lines
[ v3_req ] ... #subjectAltName = @alt_names ...
Generate a key for the IPMI module of node A, under the file name already used for the server key.
$ openssl genrsa -out dc1-a-ablm001-4096.key 4096
Generate the CSR for the IPMI name of node A.
$ openssl req -new -out dc1-a-ablm001-4096.csr -key dc1-a-ablm001-4096.key -config openssl-balabit.cnfoutput 12 lines
Country Name (2 letter code) [XX]:<COUNTRY> State or Province Name (full name) []: Locality Name (eg, city) [Default City]:Site 1 Organization Name (eg, company) [Default Company Ltd]:Example Org Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []:dc1-a-ablm001.mgmt.example.net Email Address []:admin02@example.net Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []:
Check the request. No output is kept.
$ openssl req -text -noout -in dc1-a-ablm001-4096.csr
Out-of-band certificate, datacenter B
The same edit for node B.
$ vi openssl-balabit.cnfoutput 4 lines
[ v3_req ] ... #subjectAltName = @alt_names ...
Generate a key for the IPMI module of node B.
$ openssl genrsa -out dc1-b-ablm001-4096.key 4096
Generate the CSR for the IPMI name of node B.
$ openssl req -new -out dc1-b-ablm001-4096.csr -key dc1-b-ablm001-4096.key -config openssl-balabit.cnfoutput 12 lines
Country Name (2 letter code) [XX]:<COUNTRY> State or Province Name (full name) []: Locality Name (eg, city) [Default City]:Site 1 Organization Name (eg, company) [Default Company Ltd]:Example Org Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []:dc1-b-ablm001.mgmt.example.net Email Address []:admin02@example.net Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []:
Check the request. No output is kept.
$ openssl req -text -noout -in dc1-b-ablm001-4096.csr
| Line | What it means |
|---|---|
dc1-a-ablm001.adm.example.net | a per-node name in the in-band management zone that appears nowhere else in the documents; in the design's DNS records the in-band management address belongs to the cluster only, as dc1-s-xblm001.adm.example.net |
dc1-a-ablm001.mgmt.example.net | the IPMI name of node A in the design's DNS records. Chapter 7 of the design and the network sheets name the IPMI module dc1-a-ablb001m.mgmt.example.net, the name of the final IPMI requests |
DNS.1 = scb.example.net | the user-access name; with subjectAltName commented out it is not requested at all |
admin02@example.net | the e-mail address of admin02, as in every CSR of the notes |