Step 5 of 8 · Without an agent
Devices without an agent
Copy link to the page “Devices without an agent”Without an agent, the appliance connects to the device using a login that sslbrain stores. This applies to network equipment and cloud services. Servers are connected with the service agent (Windows servers).
When a device is connected without an agent
Copy link to the section “When a device is connected without an agent”| Device | Connection | Examples from the catalogue |
|---|---|---|
| Device with SSH | SSH | VMware ESXi, pfSense, FortiMail |
| Device or service with an API | The device’s API over HTTPS | FortiGate, F5 BIG-IP, Citrix NetScaler, Kemp LoadMaster, Palo Alto, Sophos, Synology, vCenter, NetApp, Cisco FDM, Azure, AWS, Google Cloud, Cloudflare, Akamai |
The full list, and what each package can do, is under What sslbrain can install on.
The appliance must be able to reach the device: SSH on port 22, or the device’s API over HTTPS.
-
Create the device’s login under Credentials (Credentials).
-
Open Servers, click Add server, then click Device that cannot run a service agent.
-
Fill in the form:
- Hostname: the name sslbrain connects to. The appliance must be able to look it up in DNS.
- IP address (optional): only if the name cannot be looked up in DNS.
- Operating system: Appliance.
- Credentials: the login you created in step 1.
- Display name: the name in sslbrain.
-
Click Add server.
-
Open the server’s page and click Test connection.
-
Click Run discovery so sslbrain finds the services on the device.
Credentials
Copy link to the section “Credentials”Logins and keys are created under Credentials with Add credential. They are stored encrypted in the appliance’s vault and never leave it.
| Type | Used for |
|---|---|
| SSH Password, SSH Key | Devices where sslbrain delivers the certificate over SSH, for example VMware ESXi and pfSense |
| API Token | Systems with a REST API, for example a load balancer or a CDN |
| API Key + Secret | Systems that need a key pair, for example AWS or Akamai |
| DNS API | Domain validation with your DNS provider (Prove the domain is yours) |
| Custom | Free fields for an agent you have written yourself |
Minimum role to use decides who can create rules with the credential: administrator and owner, or owner only.
Devices over SSH
Copy link to the section “Devices over SSH”sslbrain sends the script to the device over SSH and runs it there. Nothing is installed on the device.
- Log in with a password (SSH Password) or a key (SSH Key). Keys can be Ed25519, ECDSA or RSA, also with a passphrase.
- The account must be able to write the certificate files and reload the service. If the account is not root, turn on Elevate via sudo on the credential, and give the account passwordless sudo for the commands that install the certificate and reload the service.
- sslbrain remembers the device’s SSH host key. If the key changes, sslbrain records it and sends a notification, but by default the installation goes ahead.
Devices and cloud services through an API
Copy link to the section “Devices and cloud services through an API”The package runs on the appliance and calls the device’s or service’s API. Nothing is installed on the device.
- Create an API Token or API Key + Secret with the permissions the package needs to upload and bind a certificate.
- Add the device with Operating system set to Appliance and the credential.
- The appliance must be able to reach the API over HTTPS.
Which devices and services have a package is listed under What sslbrain can install on.
Check that it works
Copy link to the section “Check that it works”- Test connection on the server’s page gives the status Online.
- After Run discovery, the device’s services appear under Managed Endpoints.
If it fails
Copy link to the section “If it fails”- Status Unreachable or Auth failed: A server without an agent cannot be reached.
- The certificate is not installed: Installation on the server fails.