Step 8 of 8
8. First certificate on a server
Copy link to the page “8. First certificate on a server”A rule orders the certificate through the profile, installs it on the services you choose, and installs the renewed version each time the certificate is renewed. Rules are under Deployment › Rules.
Before you start
Copy link to the section “Before you start”- The server is connected (step 5), and discovery has run on it, so its services can be chosen (discovery on the server).
- The names in the certificate are covered by a CNAME redirect or a DNS API credential (step 6).
- You know which profile the certificate is to be issued from (step 7).
- The user has the administrator or operator role.
- The Free licence has room for 10 rules; the eleventh is refused when it is created (licences).
Create the rule
Copy link to the section “Create the rule”-
Open Deployment › Rules and click Create rule. If you come from Check domain in step 6, Create a certificate for … opens the same wizard with the names filled in.
-
In the Services step, choose the services that should get the certificate (choose the services). Go on to the next step.
-
In the Certificate step, choose New certificate:
- Profile: the profile from step 7. If there is only one, it is already selected.
- Names: one name per line. The first name becomes the CN. The names are filled in from the bindings you chose. A certificate can have 1 to 100 names, including wildcards such as
*.example.dk. - Key type: types that none of the profile’s sources can issue cannot be selected.
The Domain validation panel shows for each name whether a CNAME redirect or a DNS API credential covers it. If it says that nothing covers a name, fix that in step 6 before you go on.
If the certificate is already in sslbrain, choose Use an existing certificate instead.
-
In the Summary step, give the rule a Rule name and check the settings in the table below.
-
Click Save and deploy now. The rule runs at once: it waits for the certificate and installs it when it has been issued. Save rule saves the rule without running it now.
| Setting | Default | Meaning |
|---|---|---|
| Strategy | One at a time with verification | Installs on one service at a time and waits for the installation to be confirmed. The other choices are Sequential and Parallel |
| Failure policy | Retry, roll back on failure | Tries again, and rolls back to the certificate that was there before if it still fails |
| Auto-deploy on certificate renewal | On | The renewed version is installed automatically when the certificate is renewed |
| Maintenance window | The appliance’s window from Appliance and licence › Overview, or any time if none is set | Limits when the rule may install. A window on the rule applies instead of the appliance’s. Needs Professional or Enterprise (maintenance windows) |
| Follow thumbprint (IIS) | On | After the first installation, the certificate is replaced everywhere on the server it is used |
Choose the services
Copy link to the section “Choose the services”The Services step shows Select servers and services. Search with Search servers…, and filter by OS and role (IIS, Exchange, SQL Server, RDP, AD FS, WAP, Windows CA, nginx, Apache).
- Open a server to see its services. A Windows server shows each IIS binding as
ip:port:hostname, plus Exchange services, SQL Server instances, RDP, AD FS, WAP and Dynamics NAV/Business Central. A device without an agent shows its services with the package name. - If a server shows No discovery, discovery has not run. Click Run discovery. The service agent reports the result at its next check-in, and the list updates by itself.
- The wizard goes on only when at least one service is selected.
- If the certificate is for the appliance itself, the service is on the server This appliance (the appliance’s certificate).
The package that installs comes from discovery: an IIS binding is installed with iis8plus, Exchange with exchange2013-2019, and so on. A server with a service agent needs no credential in sslbrain. The packages are listed in What sslbrain can install on.
Follow the run
Copy link to the section “Follow the run”The rule’s page has the Runs card with the status, what started the run, and the time. View run opens the details, and Execute rule starts a run.
| Status | Meaning |
|---|---|
| Queued | The run is waiting to start |
| Waiting for certificate | The certificate has been ordered but not issued yet |
| Running | The installation is in progress |
| Success / Completed | Installed |
| Partial | Some services succeeded, others failed |
| Failed | The run stopped with an error |
| Skipped | The service was skipped, for example because the server is not covered by the licence |
The run’s page shows the package, action, status, error code and duration for each service, and under Troubleshooting every step from fetching the certificate to its installation and verification. Deployment › Runs (Run log) shows every installation across rules, and Run again repeats a single installation.
Scheduled
Copy link to the section “Scheduled”Deployment › Scheduled (Scheduled runs) shows the certificate sources with their interval and next and latest run, and the row Opdateringstjek (brain + agenter), which runs every 4 hours and can be paused. The row is shown in Danish. Rules and certificates due for renewal are not listed here. Renewal is controlled as described in renewal.
sslbrain checks every 3 hours which certificates are due for renewal. There is no setting for it.
| Certificate lifetime | Renewed |
|---|---|
| 90 days or less | When two thirds of the lifetime has passed; for a 90-day certificate, about 30 days before expiry |
| Longer than 90 days | 30 days before expiry |
| All | No later than 7 days before expiry |
When the renewed version has been issued, the rule installs it if the rule is active and Auto-deploy on certificate renewal is on, within the maintenance window. The operation mode, Auto or Manual, has no effect on renewal.
Check that it works
Copy link to the section “Check that it works”A green run means that sslbrain has recorded the installation. It does not mean the server delivers the certificate. Check both.
-
Open Certificates › Managed by sslbrain and expand the certificate. Under Rules, the server is listed with Installed and Latest run, and the version reads, for example,
v1 on 1/1. The Installed count is the installations sslbrain has recorded; the server is not read again. -
Open the certificate and note the Serial and expiry date of the latest version under Versions.
-
Fetch the certificate from the server as a client sees it. Use the name in the certificate and the port the service answers on. Use 443 for a web server.
Terminal window openssl s_client -connect <servername>:<port> -servername <servername> </dev/null 2>/dev/null \| openssl x509 -noout -serial -enddateTerminal window $name = '<servername>'$tcp = [Net.Sockets.TcpClient]::new($name, <port>)$ssl = [Net.Security.SslStream]::new($tcp.GetStream(), $false, { $true })$ssl.AuthenticateAsClient($name)$cert = [Security.Cryptography.X509Certificates.X509Certificate2]::new($ssl.RemoteCertificate)$cert.SerialNumber; $cert.NotAfter$ssl.Dispose(); $tcp.Dispose()In a browser: open the address, click the padlock by the address bar, and view the certificate.
-
Compare the serial and expiry with the version in sslbrain. If they match, the server is delivering the certificate sslbrain installed.
From the appliance you can also scan the server under Find servers › TLS scanning (TLS scanning).
If it fails
Copy link to the section “If it fails”- The run stays at Waiting for certificate, or the certificate is not issued: see Validation fails.
- The run shows Failed or Partial: open the run and read the error code under Troubleshooting. See Deployment fails.
- The server still delivers the earlier certificate after a green run: the service uses a different certificate from the one the package replaced. Run discovery on the server again and check that the right binding is selected in the rule. See Deployment fails.
- The certificate is not renewed in time: see Renewal fails.