Copyright © 2000-2011 BalaBit IT Security Ltd.
November 14, 2011
Table of Contents
Welcome to BalaBit Shell Control Box (SCB) version 3 F2 and thank you for choosing our product. This document describes the new features and most important changes since the latest release of SCB. The main aim of this paper is to aid system administrators in planning the migration to the new version of SCB. The following sections describe the news and highlights of SCB 3 F2.
This document covers the BalaBit Shell Control Box 3 F2 and Audit Player 2011.3 products.
![]() |
Note |
|---|---|
For step-by-step instructions on upgrading to 3 F2 see the How to upgrade to BalaBit Shell Control Box 3 F2 at http://www.balabit.com/support/documentation/. |
As of June 2011, the following release policy applies to BalaBit Shell Control Box:
Long Term Supported or LTS releases (for example, SCB 3 LTS) are supported for 3 years after their original publication date and for 1 year after the next LTS release is published (whichever date is later). The second digit of the revisions of such releases is 0 (for example, SCB 3.0.1). Maintenance releases to LTS releases contain only bugfixes and security updates.
Feature releases (for example, SCB 3 F1) are supported for 6 months after their original publication date and for 2 months after succeeding Feature or LTS Release is published (whichever date is later). Feature releases contain enhancements and new features, presumably 1-3 new feature per release. Only the last feature release is supported (for example when a new feature release comes out, the last one becomes unsupported within two months).
For a full description on stable and feature releases, see Stable and feature releases.
Implementing a single-sign-on solution for administrators and other privileged users using remote access can greatly simplify the password management on the remote servers and also improves the access control possibilities.
Credential Stores offer a way to store user credentials (for example, passwords, private keys, certificates) and use them to login to the target server, without the user having access to the credentials. That way, the users only have to authenticate on SCB with their usual password (that can be stored locally on SCB or in your central LDAP database). If the user is allowed to access the target server, SCB automatically logs in using the data from the Credential Store. In a sense, using Credential Stores is an improved version of the keymapping available for SSH connections.
In addition to storing credentials locally, SCB integrates smoothly to Enterprise Random Password Manager (ERPM), Lieberman Software's privileged identity management solution. That way, the passwords of the target servers can be managed centrally using the ERPM, while SCB ensures that the protected servers can be accessed only via SCB — since the users do not know the passwords required for direct access.
SCB supports creating custom reports and custom statistics, including user-created statistics and charts based on search results, the contents of audit trails, and other customizable content. Reports from custom queries executed on the databases of SCB can be created as well. For details, see Chapter 6, Browsing log messages and SCB reports in
Custom reports created in earlier SCB versions from the contents of audit trails are now available as report subchapters and can be included in multiple reports. The search keywords and other search-related parameters of existing custom reports can be modified on the page, while other parameters of the report can be modified on the page of the SCB web interface.
To simplify auditing the privileges and permissions of SCB users and usergroups, the page can display the privileges for the SCB web interface itself, as well as the parameters of connections that can be accessed by users or usergroups. For details, see Section 4.4.8, Displaying the privileges of users and user groups in
SCB has supported compression in RDP connections since version 3.0. However, it was found that enabling compression in certain RDP channels causes problems: most notably, files copied in disk redirection channels can become corrupt in certain situations. Therefore, although compression support for RDP connections is enabled by default in SCB version 3.2, it can be disabled by unchecking the option.
Note that disabling compression significantly increases the network load of RDP connections. The exact ratio of the increase depends on the content of the connections, but on the average the network load can be expected to increase by 500%.
The usergroups of Channel Policies are treated separately on the client side (Gateway group) and the server side (Remote group). For details on how separating these groups is handled when upgrading an existing configurations, see Section 3, Gateway groups and remote groups in
Starting with SCB version 3 F2, SSH connections that use Usermapping Policies must use gateway authentication as well. If you have any SSH Connection Policies that have a Usermapping Policy set but do not require gateway authentication (either inband or outband), adjust these Connection Policies to require gateway authentication.
In Bridge mode, SCB forwards DHCP traffic between the external and internal interfaces. However, other multicast and broadcast traffic is blocked.
The option has been renamed to .
SCB automatically disables font smoothing (antialiasing) in Citrix ICA connections to improve text recognition in the Audit Player.
SCB automatically disables antialiasing in RDP connections to improve text recognition in the Audit Player. Note that only a few recent RDP client versions had antialiasing enabled by default.
This section describes the main changes of the Audit Player version 3 F2 application.
It is possible to search for specific keyboard or mouse events.
The timeline of the audit trail shows display changes and user-input events.
When replaying an audit trail, the idle periods can be skipped.
Loading audit trail files is significantly faster.
© 2007-2011 BalaBit IT Security
Please send your comments or documentation bugs to: documentation@balabit.com