Skip to content

Step 2 of 8

The setup wizard makes the appliance yours: it is linked to your sslbrain Cloud account, gets a licence and the 12 backup words, and you decide how it updates itself. The wizard has five steps. This page covers the first four, and step 3 of the manual covers the fifth, the name.

  • The appliance has started and answers in the browser. Open the address the console or the installation showed, for example https://192.168.1.20. A fresh appliance redirects every page to /setup until the wizard is complete.
  • The browser warns about the certificate. This is expected: the appliance created a self-signed certificate on first boot, and it can be replaced in step 3.
  • The person running the wizard is an owner or administrator on the sslbrain Cloud account. That person becomes the owner (Owner) of the appliance.
  • The appliance can reach cloud.sslbrain.com, acme.sslbrain.com and registry.sslbrain.com on port 443.
  • Have somewhere ready for the 12 backup words: paper in a locked cabinet, or a password manager that is not on the appliance itself.

Step 1 of the wizard links the appliance to your account. There is no code to type.

  1. Click Log in with sslbrain Cloud. The browser goes to sslbrain Cloud.

  2. Log in and confirm that the appliance is yours. If you have no account, create one there. The browser returns to the address you opened the appliance on.

  3. The wizard moves on to the licence choice by itself.

If the computer with the browser cannot reach sslbrain Cloud, click Copy link and open the link somewhere else, for example on a phone. Log in there, and paste the code you are given under Logged in somewhere else? Paste the code from there:. Click Continue with the code.

If the appliance itself cannot reach sslbrain Cloud, the wizard shows “The appliance could not reach sslbrain Cloud” and the list Addresses for the firewall. Open outbound 443 to those addresses and try again. Use the names in the firewall if it supports them: the addresses behind the names can change.

The confirmation in sslbrain Cloud is valid for about a day. If it has expired, the wizard sends you back to step 1 and you log in again.

Step 2 of the wizard, Choose a licence, shows who you are signed in as and which licences the account has free.

  1. Check the line “Signed in as …”. If it is the wrong account, click Wrong account? Log in again.

  2. Choose the licence:

    ChoiceWhen
    FreeThe Free licence. It covers 5 servers and 10 rules.
    Paid plan with the plan’s nameA Basic, Professional or Enterprise licence the account has bought. If the payment has not been registered yet, the appliance runs on a temporary licence until the date shown.
    Move the licence from with the name of another applianceThis appliance is to take over the licence from another one. The other appliance keeps running until this one takes over, and is then retired. See Move or restore the appliance.
  3. Click Use this licence.

If the wizard shows “This account has no licence free right now.”, buy a licence or release an installation in sslbrain Cloud. The list refreshes itself once a licence is free. If the wizard asks you to accept the licensing terms and the data processing agreement, do so in sslbrain Cloud and log in again.

The limits of each licence are under Licences and units.

Step 3 of the wizard is called Emergency key and shows 12 English words. The words are the only way into the appliance’s data if sslbrain Cloud cannot be reached.

  1. Write down the 12 words in order, or click Copy key and store them in a password manager.

  2. Keep them somewhere you can find them when both the appliance and sslbrain Cloud are down.

  3. Tick I have saved the recovery key somewhere safe. and click Next.

The words open the appliance’s vault without sslbrain Cloud, sign in as the Admin Local account via Log in with backup words on the login page, and unlock the appliance again after a restore from backup. See Security and Backup.

Step 4 of the wizard, Operation and diagnostics, has three choices on one screen.

  1. Choose Auto or Manual. Neither is selected in advance.

  2. Tick Share diagnostics with FairSSL continuously. if FairSSL may receive diagnostics from the appliance. See Share diagnostics with FairSSL.

  3. Under Service agent updates, choose how the service agents on your servers are updated. See Service agent updates.

  4. Click Continue.

The operation mode sets the starting value of four switches, which you afterwards change one by one under Updates › Automation:

SwitchAutoManual
Appliance updates: signed updates of the appliance are installed automaticallyonoff
Modules: modules are updated automaticallyonoff
Agent packages: new versions of the agent packages are downloaded automaticallyonoff
Automatic agent approval: a new service agent with a valid token or install code is let in without approvalonoff

With Manual, every new service agent waits for an administrator to approve it. See Approve the server. New versions of the agent packages must also be approved under Agents › Settings before they are used. The versions the appliance shipped with are approved in your name.

The operation mode does not control certificate renewal. Certificates renew the same way with either choice.

Licence modules are downloaded during setup with either choice, but they are not activated. You do that under Modules. What each switch starts is described under Keep sslbrain up to date, and Policy and audit › Operation mode shows afterwards what was chosen and what the switches are set to now. See Policy and audit.

The Share diagnostics with FairSSL continuously. box is unticked to begin with. If you tick it, the appliance sends logs, errors, agent runs, certificate metadata and configuration to FairSSL at the first exchange and then about every 15 minutes. Passwords, tokens and private keys are removed before anything is sent.

The screen refers to “Settings → Diagnostics”. In the menu, the place is Maintenance and support › Diagnostics, and there you can deselect sections or switch the whole thing off. See Support and diagnostics.

Under Service agent updates, you choose how the service agents on your servers get new versions:

ChoiceWhat happens
Automatic (recommended)Selected by default. sslbrain updates to the newest version in FairSSL’s signed catalogue by itself: one server first, then a few at a time. If an update fails, the automatic rollout of that version stops.
ManualAn administrator chooses the version and updates from the server’s page or from Servers.

The server checks FairSSL’s signature itself before it installs. If the new version does not report in within 10 minutes, the server reinstalls the version it was running before. The Off choice is available afterwards under Updates, and only the owner can change the setting. See Keep service agents up to date.

After Continue, the wizard moves on to its step 5, Access and hostname, which step 3 of the manual describes.

  • The wizard’s header shows Step 5 of 5: Access and hostname.
  • In sslbrain Cloud, the appliance is listed under Appliances with the licence you chose.
  • The 12 backup words are stored somewhere outside the appliance.