Step 5 of 8 · Linux
Linux servers
Copy link to the page “Linux servers”The Linux service agent is a systemd service. It fetches certificates from the appliance and installs them on the server.
Before you start
Copy link to the section “Before you start”You need:
- An x86_64 or arm64 server with systemd.
- Root access to the server, or an account with sudo.
- The server can reach the appliance. If it is somewhere other than the appliance, see Servers outside your network.
Install the agent
Copy link to the section “Install the agent”-
Open Agents › Install in sslbrain and choose Linux.
-
Choose Manual installation and click Download installer. Copy the file to the server.
-
Unpack the file on the server and go into the folder:
Terminal window tar -xzf sslbrain-agent-linux-<version>.tar.gzcd sslbrain-agent-linux-<version> -
Open Agents › Install codes in sslbrain. Enter the server’s name in Name and click Create code. Leave the other fields as they are. Keep the page open. The code is shown this one time only.
-
Put the code in a file only root can read. Run the command, paste Install code, press Enter and then Ctrl-D:
Terminal window sudo sh -c 'umask 077; cat > /root/sbi.code' -
Copy the command under Linux and add
--profile deployat the end. It looks like this:Terminal window sudo ./install.sh --code-file /root/sbi.code --destinations "<addresses>" --profile deploy -
Run the command in the folder from step 3.
-
Delete the file with the code:
Terminal window sudo rm /root/sbi.code
Without --profile deploy the agent can find certificates but not install them.
A code works on one server, once.
The server shows up
Copy link to the section “The server shows up”Once the agent has checked in, the server is listed under Waiting for approval on Agents › Install codes.
-
Compare Agent key with the key the agent has written to its log on the server (Log files).
-
Click Approve.
If the server was approved automatically, it is already listed under Servers and you skip these steps.
The server is now listed under Servers. sslbrain looks for Nginx and Apache on the server by itself and lists what it finds under Managed Endpoints.
Next step
Copy link to the section “Next step”Prove the domain is yours, so sslbrain can get certificates for it: Prove the domain is yours.
If it fails
Copy link to the section “If it fails”- install.sh says “—code-file does not hold an install code”: the file does not hold the whole code. A code starts with
sbi1.. - install.sh says “this package has no protocol core”: the server is neither x86_64 nor arm64.
- A tool is missing: the script needs bash 4.4 or later,
openssl,tar,curlorwget,flock,timeout,base64,find,odandsed. If bothcurlandwgetare missing, the script installscurlitself. - The server has no systemd: add
--mode cronto the command. - The server does not trust the appliance’s certificate: give the appliance the free name (The free name).
- The agent finds certificates but does not install them: it was installed without
--profile deploy. Runinstall.shfrom the package again with--profile deploy. - The server does not show up: read the agent’s log (Log files) and check that the server can reach the appliance (The agent does not check in.
- The certificate is not installed: Installation fails.
Log files
Copy link to the section “Log files”The agent writes to the journal:
systemctl status sslbrain-agent.servicejournalctl -u sslbrain-agent.service -n 50 --no-pagerWith --mode cron the log is in /var/lib/sslbrain/state/agent.log.
install.sh options
Copy link to the section “install.sh options”| Option | Meaning |
|---|---|
--code-file <file> | File with an install code, or - for standard input |
--destinations <list> | Addresses in order of priority, comma-separated, cloud for sslbrain Cloud |
--profile deploy | Runs as root, installs certificates and reloads services |
--profile scoped | Writes only in the certificate folders you give it access to, and reloads the service through a hook owned by root. Needs local setup |
--profile inventory | Finds and monitors certificates but installs none. The default when --profile is missing |
--mode systemd|timer|cron | How the agent runs. The default is systemd |
--cloud-deny | The agent never contacts sslbrain Cloud, whatever the appliance sends |
--url <address>, --token <token> | The appliance’s address and the registration token, for installing without an install code |
--verify-tls, --ignore-tls | Check the appliance’s certificate, or do not (unsafe). Cannot be combined with --code-file |
Run again without --profile, the agent keeps its profile. The agent is in /usr/local/lib/sslbrain/sslbrain-agent, its settings in /etc/sslbrain/agent.conf and its state in /var/lib/sslbrain/state.