Step 5 of 8 · Updates
Keep service agents up to date
Copy link to the page “Keep service agents up to date”The appliance can update the service agent on your servers to a newer version. Only versions in FairSSL’s signed catalogue can be chosen, and the server checks FairSSL’s signature itself before installing. If the new version does not check in within 10 minutes, the server reinstalls the version it was running before.
Choose how the agents are updated
Copy link to the section “Choose how the agents are updated”The Service agent updates card is under Updates. Only the owner can change it, and the change is recorded in the audit log.
| Choice | What happens |
|---|---|
| Automatic (recommended) | sslbrain updates to the newest version in the catalogue by itself: one server first, then a few at a time |
| Manual | An administrator chooses the version and updates from the server’s page or from the server list |
| Off | sslbrain sends no updates to the service agents |
The starting value was chosen at setup (Service agent updates).
The card also shows which versions the catalogue holds: Catalog: Windows … · Linux …. The appliance fetches FairSSL’s catalogue from sslbrain Cloud every hour.
With Automatic, sslbrain updates one server first. Once that has succeeded, at most 10 % of the agents on the same platform are updated at a time, and only agents that have checked in within the last 15 minutes. The automatic rollout runs once an hour. If an update fails, the automatic rollout of that version stops.
The switch Agent packages under Updates › Automation concerns the packages the agents run (for example IIS or Exchange). It does not update the service agent itself.
Update one server
Copy link to the section “Update one server”-
Open the server under Servers.
-
The Service agent panel shows the installed version, and the newest version in the catalogue when there is a newer one.
-
Choose the version under Version and click Update.
-
Confirm. The service restarts on the server once it has fetched the update.
The server fetches the update the next time the agent checks in. The panel shows the status as it goes, for example “Update 1.3.2 → 1.3.3 is waiting for the agent to fetch it” and finally “Updated from 1.3.2 to 1.3.3”.
Update many servers at once
Copy link to the section “Update many servers at once”-
Open Servers.
-
Select the servers to update.
-
Click Update service agents with the number in brackets, and confirm.
Every selected server is updated to the newest version in the catalogue. The appliance replies with how many updates were sent and how many were skipped, for example because the agent already has that version or is too old to update itself.
The first time an update is sent, the appliance may ask to download and activate FairSSL’s update agent: Download, activate and update or Activate and update. Only an update agent signed by FairSSL is activated, and the activation is recorded in the audit log.
If an update does not succeed
Copy link to the section “If an update does not succeed”The server rolls back by itself. If the new version does not check in within 10 minutes, the server reinstalls the version it was running before, even if that version is no longer in the catalogue. The appliance shows “Update to … rolled back to …” after 15 minutes.
An update the agent has not fetched within 24 hours is abandoned. The MSI file refuses to install an older version over a newer one.
Agents that cannot be updated from the appliance
Copy link to the section “Agents that cannot be updated from the appliance”| Agent | Can be updated from the appliance |
|---|---|
| Windows agent from version 1.3.1 | Yes |
| Windows agent 1.1.x and 1.2.x | No. Install a newer MSI file on the server once |
An agent that cannot update itself shows “This service agent cannot update itself” on the server’s page.
Update a Windows agent by hand with the newest MSI file from Agents › Install (Download the MSI file). The address, the enrolment and the settings are kept, so the command needs no properties:
msiexec /i sslbrain-agent-v<version>-win-x64.msi /qn /norestartOnce the agent runs a version from the list above, it can be updated from the appliance.
Agents installed without an install code
Copy link to the section “Agents installed without an install code”The server’s page shows whether the agent is Installed with an install code or says “The agent is installed without an install code”. An agent installed with the registration token moves itself over to an install code once it runs the Windows agent from version 1.3.3.
- The agent asks the appliance for a code over its existing connection and enrols with it. The appliance approves it automatically, because it already knows the agent.
- The agent keeps its agent ID, its server, its rules and its settings. No new server is created.
- From the agent’s first check-in with the install code, the appliance refuses the agent’s token and client certificate.
- If the appliance refuses the move, or it does not finish within two hours, the agent carries on with the registration token and tries again later.
- Once the agent has moved, it follows Agents › Connection and can use sslbrain Cloud if that is turned on (How the agent reaches the appliance).
An agent does not move itself if it runs with IGNORETLS=1, or if it has never pinned the appliance’s certificate. Such an agent, and agents before version 1.3.3, are installed again with an install code (Install with an install code). The Create an install code button is in the Service agent panel. The server’s rules and certificates are kept.
Agents that reach the appliance only through sslbrain Cloud
Copy link to the section “Agents that reach the appliance only through sslbrain Cloud”A Windows agent that reaches the appliance only through sslbrain Cloud cannot be updated from the appliance. See Updating agents that reach the appliance only through sslbrain Cloud.
Check that it works
Copy link to the section “Check that it works”- The server’s page shows the new version in the Service agent panel and “Updated from … to …”.
- On the server,
Get-Service SSLBrainAgentshows statusRunning.
If it fails
Copy link to the section “If it fails”- “sslbrain has not fetched FairSSL’s catalog of service agent versions yet.”: the appliance must be connected to sslbrain Cloud. The catalogue is fetched every hour.
- “Service agent updates are off.”: the owner must choose Manual or Automatic under Updates.
- “The update agent is not in the agent catalogue”: the appliance could not fetch FairSSL’s update agent from sslbrain Cloud. Try again later.
- Status “rolled back”: the new version did not check in within 10 minutes. See the update log
update-msiexec-<version>-<time>.logand the agent’s log on the server (Log files). - The agent does not fetch the update because it does not check in: A service agent does not check in.