Skip to content

Step 5 of 8 · Linux

The Linux service agent is a systemd service. It fetches certificates from the appliance and installs them on the server.

You need:

  • An x86_64 or arm64 server with systemd.
  • Root access to the server, or an account with sudo.
  • The server can reach the appliance. If it is somewhere other than the appliance, see Servers outside your network.
  1. Open Agents › Install in sslbrain and choose Linux.

  2. Choose Manual installation and click Download installer. Copy the file to the server.

  3. Unpack the file on the server and go into the folder:

    Terminal window
    tar -xzf sslbrain-agent-linux-<version>.tar.gz
    cd sslbrain-agent-linux-<version>
  4. Open Agents › Install codes in sslbrain. Enter the server’s name in Name and click Create code. Leave the other fields as they are. Keep the page open. The code is shown this one time only.

  5. Put the code in a file only root can read. Run the command, paste Install code, press Enter and then Ctrl-D:

    Terminal window
    sudo sh -c 'umask 077; cat > /root/sbi.code'
  6. Copy the command under Linux and add --profile deploy at the end. It looks like this:

    Terminal window
    sudo ./install.sh --code-file /root/sbi.code --destinations "<addresses>" --profile deploy
  7. Run the command in the folder from step 3.

  8. Delete the file with the code:

    Terminal window
    sudo rm /root/sbi.code

Without --profile deploy the agent can find certificates but not install them.

A code works on one server, once.

Once the agent has checked in, the server is listed under Waiting for approval on Agents › Install codes.

  1. Compare Agent key with the key the agent has written to its log on the server (Log files).

  2. Click Approve.

If the server was approved automatically, it is already listed under Servers and you skip these steps.

The server is now listed under Servers. sslbrain looks for Nginx and Apache on the server by itself and lists what it finds under Managed Endpoints.

Prove the domain is yours, so sslbrain can get certificates for it: Prove the domain is yours.

  • install.sh says “—code-file does not hold an install code”: the file does not hold the whole code. A code starts with sbi1..
  • install.sh says “this package has no protocol core”: the server is neither x86_64 nor arm64.
  • A tool is missing: the script needs bash 4.4 or later, openssl, tar, curl or wget, flock, timeout, base64, find, od and sed. If both curl and wget are missing, the script installs curl itself.
  • The server has no systemd: add --mode cron to the command.
  • The server does not trust the appliance’s certificate: give the appliance the free name (The free name).
  • The agent finds certificates but does not install them: it was installed without --profile deploy. Run install.sh from the package again with --profile deploy.
  • The server does not show up: read the agent’s log (Log files) and check that the server can reach the appliance (The agent does not check in.
  • The certificate is not installed: Installation fails.

The agent writes to the journal:

Terminal window
systemctl status sslbrain-agent.service
journalctl -u sslbrain-agent.service -n 50 --no-pager

With --mode cron the log is in /var/lib/sslbrain/state/agent.log.

OptionMeaning
--code-file <file>File with an install code, or - for standard input
--destinations <list>Addresses in order of priority, comma-separated, cloud for sslbrain Cloud
--profile deployRuns as root, installs certificates and reloads services
--profile scopedWrites only in the certificate folders you give it access to, and reloads the service through a hook owned by root. Needs local setup
--profile inventoryFinds and monitors certificates but installs none. The default when --profile is missing
--mode systemd|timer|cronHow the agent runs. The default is systemd
--cloud-denyThe agent never contacts sslbrain Cloud, whatever the appliance sends
--url <address>, --token <token>The appliance’s address and the registration token, for installing without an install code
--verify-tls, --ignore-tlsCheck the appliance’s certificate, or do not (unsafe). Cannot be combined with --code-file

Run again without --profile, the agent keeps its profile. The agent is in /usr/local/lib/sslbrain/sslbrain-agent, its settings in /etc/sslbrain/agent.conf and its state in /var/lib/sslbrain/state.