Skip to content

Step 5 of 8

Once a server is connected, sslbrain can find the services on it and install certificates on it. Windows servers get a service agent. Network equipment and cloud services that cannot run an agent are connected without an agent.

The service agent is the recommended connection for Windows servers. It is installed on the server and contacts the appliance itself over outbound HTTPS. You do not open any port into the server, and sslbrain does not store the server’s login.

  • The agent collects its tasks from the appliance when it checks in, and runs them locally.
  • It checks the signature on every script before running it. By default it runs FairSSL’s packages and no scripts of your own. The agent’s script policy on the server decides this (Your own scripts).
  • When a server has a service agent, sslbrain runs every task on that server through the agent, including packages that would otherwise connect from the appliance (How packages run).
Server or deviceConnectionGuide
Windows ServerService agentWindows servers
Firewall, load balancer, NAS, cloud serviceThe device’s API, or SSH from the applianceDevices without an agent

If you have many Windows servers, read Roll out the service agent to many Windows servers before installing on them one at a time.

The service agent must be able to reach the appliance. There are two routes, and an agent can have both.

Directly to the appliance. The server reaches the appliance’s address over HTTPS, port 443 by default. This covers servers on the same network as the appliance or connected to it by VPN. See How the agent reaches the appliance.

Through sslbrain Cloud. For servers in branch offices, at a hosting provider or behind a firewall with no route to the appliance. The agent and the appliance exchange encrypted messages through sslbrain Cloud, and both sides connect outbound only. This needs a Professional or Enterprise licence and an agent installed with an install code. See Servers outside your network.

An agent with both routes uses the direct address first and sslbrain Cloud when the direct route does not answer (The order).

A new service agent becomes a server in sslbrain only once it is approved. It is approved automatically when both of these hold:

  • the agent was installed with the appliance’s Registration token from Agents › Install, or with an install code that has Approve automatically turned on;
  • the switch Automatic agent approval under Updates › Automation is on (Automation).

The operation mode chosen at setup gave the switch its starting value: Auto turned it on, Manual turned it off (Operation mode). From then on the switch decides.

A machine that looks like a reinstall of a server sslbrain already knows (same host name, machine ID or IP address) always waits for an administrator.

Where a waiting machine appears depends on how the agent was installed:

Installed withWaits underApprove with
Registration token (Agents › Install)Servers, in the box Venter på godkendelseGodkend or Afvis. A reinstall has Approve as reinstall and Approve as new server
Install codeAgents › Install codes, under Waiting for approvalCompare the Agent key with the key the agent writes to its log on the server, then click Approve
  1. Open the list where the machine is waiting (table above).

  2. Check that the host name, operating system and agent version match the server you installed on. Approve only machines you recognise.

  3. Click Godkend or Approve. If the machine is a reinstall, choose Approve as reinstall: the server sslbrain knows, and its rules, move over to the reinstalled agent.

Only an administrator can approve. At most 500 machines can wait for approval at a time. A machine with an install code that has not been approved within 14 days gets the status Not approved in 14 days and must be installed again with a new code.

Every connected server is listed under Servers. The list shows host name, name, operating system, IP address, status, Last seen and the number of Managed Endpoints.

StatusMeaning
OnlineThe server is connected
UnreachableTest connection could not reach the server
Auth failedTest connection reached the server, but the login with the credential was refused

Last seen shows when the server was last in contact with the appliance. If a service agent has not checked in for more than a day, the server’s page says so.

The row This appliance is the appliance itself. It is used when a certificate is to be installed on the appliance.

The licence covers a number of servers. Servers beyond that number are marked as deactivated because the licence does not cover them, and they get no certificates. The licence covers the oldest servers first.

The server’s own page has the panel Service agent with status, version, Last check-in and whether the agent is Installed with an install code or without one. This is also where the agent is updated (Keep service agents up to date).

Once an agent is approved, sslbrain starts discovery on the server by itself. The result arrives the next time the agent checks in. Until then the server’s page shows “Discovery running”.

On a Windows server, discovery looks for IIS, Remote Desktop, Exchange, SSL bindings (netsh), Windows CA (AD CS), Web Application Proxy and the certificates in the Windows certificate store.

  • The services it finds appear on the server’s page under Managed Endpoints.
  • Certificates found on the server appear under Certificates › Found on servers (Certificates on the servers).
  • sslbrain repeats discovery by itself, once a month by default (the run is at 02:00).
  • If you have installed a new service, click Run discovery on the server’s page.

Discovery must have run before the server’s services can be chosen as the target of a rule in step 8 (Choose the services).

  • The server is listed under Servers with status Online and a recent time in Last seen.
  • Once discovery has finished, the server’s page shows at least one service under Managed Endpoints.