Skip to content

Step 5 of 8 · Without an agent

Without an agent, the appliance connects to the device using a login that sslbrain stores. This applies to network equipment and cloud services. Servers are connected with the service agent (Windows servers).

DeviceConnectionExamples from the catalogue
Device with SSHSSHVMware ESXi, pfSense, FortiMail
Device or service with an APIThe device’s API over HTTPSFortiGate, F5 BIG-IP, Citrix NetScaler, Kemp LoadMaster, Palo Alto, Sophos, Synology, vCenter, NetApp, Cisco FDM, Azure, AWS, Google Cloud, Cloudflare, Akamai

The full list, and what each package can do, is under What sslbrain can install on.

The appliance must be able to reach the device: SSH on port 22, or the device’s API over HTTPS.

  1. Create the device’s login under Credentials (Credentials).

  2. Open Servers, click Add server, then click Device that cannot run a service agent.

  3. Fill in the form:

    • Hostname: the name sslbrain connects to. The appliance must be able to look it up in DNS.
    • IP address (optional): only if the name cannot be looked up in DNS.
    • Operating system: Appliance.
    • Credentials: the login you created in step 1.
    • Display name: the name in sslbrain.
  4. Click Add server.

  5. Open the server’s page and click Test connection.

  6. Click Run discovery so sslbrain finds the services on the device.

Logins and keys are created under Credentials with Add credential. They are stored encrypted in the appliance’s vault and never leave it.

TypeUsed for
SSH Password, SSH KeyDevices where sslbrain delivers the certificate over SSH, for example VMware ESXi and pfSense
API TokenSystems with a REST API, for example a load balancer or a CDN
API Key + SecretSystems that need a key pair, for example AWS or Akamai
DNS APIDomain validation with your DNS provider (Prove the domain is yours)
CustomFree fields for an agent you have written yourself

Minimum role to use decides who can create rules with the credential: administrator and owner, or owner only.

sslbrain sends the script to the device over SSH and runs it there. Nothing is installed on the device.

  • Log in with a password (SSH Password) or a key (SSH Key). Keys can be Ed25519, ECDSA or RSA, also with a passphrase.
  • The account must be able to write the certificate files and reload the service. If the account is not root, turn on Elevate via sudo on the credential, and give the account passwordless sudo for the commands that install the certificate and reload the service.
  • sslbrain remembers the device’s SSH host key. If the key changes, sslbrain records it and sends a notification, but by default the installation goes ahead.

The package runs on the appliance and calls the device’s or service’s API. Nothing is installed on the device.

  • Create an API Token or API Key + Secret with the permissions the package needs to upload and bind a certificate.
  • Add the device with Operating system set to Appliance and the credential.
  • The appliance must be able to reach the API over HTTPS.

Which devices and services have a package is listed under What sslbrain can install on.

  • Test connection on the server’s page gives the status Online.
  • After Run discovery, the device’s services appear under Managed Endpoints.