Skip to content

The appliance writes every change to an audit log with a hash chain. One setting decides who can download private keys, and four switches decide what the appliance does without a person.

When an auditor, your management or a customer asks who changed what on the appliance, who can download private keys, which domains can get certificates, and which changes the appliance makes by itself.

Every role can read the audit log, including Viewer. Give the auditor a login with the Viewer role: they can read the log but change nothing. A login counts towards the licence’s number of logins, see Users and sign-in.

The log is under Policy and audit › Audit log.

  • Every change to data on the appliance: servers, certificates, profiles, sources, rules, users and settings.
  • Login, logout, failed logins and logins with the 12 backup words.
  • Creating, downloading and restoring backups, and refused downloads.
  • When the vault is locked and opened.
  • The choice of operation mode, consent to diagnostics, and the private key export setting.

Secret values such as passwords and keys are not written to the log. Settings that the appliance updates by itself are not written either.

The log can be filtered by action, user, entity type, object ID and time range (From and To), and searched as free text. It shows 50 rows per page, and Show diff shows each field’s value before and after.

Each row carries a hash of the previous row’s hash and the row’s own content. The Chain column shows Chained for rows in the chain and No hash for rows without one.

The appliance checks the chain every night. The check finds rows that have been edited, deleted, moved or inserted afterwards. It does not find a log rewritten in full by someone with access to the database file itself.

The licence decides how long rows are kept:

LicenceAudit log on the applianceAudit log in sslbrain Cloud
Free30 days7 days
Basic90 days90 days
Professional730 days365 days
Enterprise2555 days1095 days

The Audit log card under Appliance and licence › Overview shows the figure for the appliance: “The audit log is kept for … days, as your licence sets.” If the licence gives fewer days than before, the appliance waits 30 days before it deletes anything, and the card shows the date.

Export CSV and Export JSON need Professional or Enterprise and the Operator role or higher. Without that licence the page shows “Exporting the audit log requires Professional or Enterprise.” The file is called audit-log-<date>, and the column headings in the CSV file are always in Danish.

A root shell opened from the console menu (9 Danger zone, 1 Open a root shell) is recorded on the machine. The recordings stay on the machine and are not sent anywhere. 3 View recorded shell sessions shows the latest 10. See Console menu.

The Private key export card under Users and login › Login and sessions decides who can download a certificate’s private key, and only an Owner can change it. Every download is written to the audit log. The options and defaults are in Security.

On Free, an sslbrain Cloud account can hold certificates for at most 10 registrable domains, with at most 100 names per certificate. The limit applies to the whole account and is checked by sslbrain Cloud when an order is created. Basic, Professional and Enterprise have no domain limit. See Policy and audit.

To control which CAs may issue certificates for your domains, create CAA records in DNS. Certificates › Tools has a CAA generator and a CAA lookup, see Tools.

Four switches under Maintenance and support › Updates decide what the appliance does without a person:

SwitchOn means
Appliance updatesNewer signed versions of the appliance are installed automatically.
ModulesLicence modules are downloaded and kept up to date. A module is never activated automatically.
Agent packagesNew versions of agent definitions and service agent packages are downloaded.
Automatic agent approvalA new agent with a valid key from the appliance is approved without an administrator.

Policy and audit › Operation mode shows the starting choice from setup (Auto or Manual), the date it was made, and the switches’ current position under Automation now. The page cannot be changed. The switches are changed under Updates, see Keep sslbrain up to date.

Two things always happen:

  • Certificates are renewed automatically. Renewal has no switch, and the operation mode does not affect it.
  • A renewed certificate is deployed to the servers when the rule has Auto-deploy on certificate renewal on. This is chosen on each rule.

Which versions of the agent packages may run is decided under Agents › Settings. With Approve new versions automatically (recommended) off, only versions an administrator has approved in the catalogue run. Which scripts the service agent runs is decided on each server, see Policy and audit.

Every change to the switches and the operation mode is written to the audit log.