Skip to content

Step 1 of 8

sslbrain runs as an appliance on your own network. Once it answers in the browser, everything else is set up from there.

  • An sslbrain Cloud account that has accepted the licensing terms and the data processing agreement.
  • For the virtual appliance: 2 vCPU, 4 GB RAM and a 40 GB disk, thin provisioned.
  • For Docker: a Linux server with 4 GB RAM and 20 GB of free disk space.
  • VMware vSphere, ESXi, Workstation or Fusion: the OVA file. See VMware.
  • Proxmox, KVM or libvirt: the qcow2 disk image. See Proxmox and KVM.
  • Your own Linux server with Docker: the installation script. See Linux with Docker.

Hyper-V is not supported. The virtual appliance comes with a console menu, Ubuntu security updates and a ready-made firewall. With Docker, you keep the operating system up to date yourself.

On first boot, the virtual appliance downloads the newest sslbrain version by itself. This takes a few minutes.

  1. Wait until the console shows Open https://<ip> in a browser to use it.

  2. Open the address in your browser. http://<ip> redirects to HTTPS.

  3. The browser warns about the certificate, because the appliance has created a self-signed certificate. To check that it is your appliance, compare the fingerprint with the SHA-256 fingerprint under item 1 in the console menu.

  4. The setup wizard opens with the Log in with sslbrain Cloud button.

Continue with 2. First-time setup.

If sslbrain needs to look up internal names, such as servers in Active Directory, enter your internal DNS servers once setup is complete.

  1. Open Network and DNS › DNS servers. The page requires the administrator role.

  2. Enter your internal DNS servers under DNS-server IP-adresser, separated by commas. These are usually your domain controllers.

  3. Under Søgedomæner, enter the domains that short names are looked up in.

  4. Click Gem. Look up an internal name under Test DNS-opslag to check that it works.

The appliance asks your DNS servers first, then the servers it already had, and finally 1.1.1.1. Aktiv konfiguration shows what it is using now.

  • The console shows “NO NETWORK ADDRESS”: the appliance has not received an address via DHCP. Set a static address with item 3 in the console menu. The appliance carries on by itself.
  • The console shows “The IP address from the deploy wizard was refused”: the appliance has stayed on DHCP. The reason is in the message. Set the address with item 3 in the console menu.
  • The software cannot be downloaded: the appliance tries again every 30 seconds. Item 2 in the console menu shows whether the name cannot be resolved (DNS) or does not answer (firewall). See Network and firewall and No connection to sslbrain Cloud.
  • The signature check fails: the appliance does not start the software and tries again every 5 minutes. Item 4 and then item 3 in the console menu show the log file from first boot. Send it to FairSSL (Support and diagnostics).
  • The browser cannot reach the appliance: see the status and address under item 1 in the console menu.

The appliance only needs outbound connections to the internet. Use the names in the firewall if it supports them, because the addresses behind them can change.

FromToPortUsed for
The appliancecloud.sslbrain.com443Activation, licence and sslbrain Cloud
The applianceacme.sslbrain.com443Certificate issuance
The applianceregistry.sslbrain.com443The appliance’s software and updates
The virtual appliancearchive.ubuntu.com, security.ubuntu.com80Ubuntu security updates

Without port 80 the appliance runs, but Ubuntu gets no security updates. Ubuntu restarts at 03:00 when an update requires it.

On your own network:

FromToPort
Browsers and service agentsThe appliance443 on the virtual appliance, 8443 with Docker
The applianceDevices without an agent, via SSH22
The applianceDevices managed via APIthe device’s HTTPS port
The applianceThe DNS provider’s API, if you use a DNS API for domain validation443

The virtual appliance uses DHCP. A static address is entered during import: as OVF properties in VMware, or on a seed disk in Proxmox and KVM. The address is read once, at first boot. After that, you change the address with item 3 in the console menu (Console menu). Without DNS servers, the appliance uses 1.1.1.1 and 9.9.9.9.

The virtual machine’s console shows a menu in English instead of a login prompt. Every item is described under Console menu. A Docker installation has no console menu.

CPU and RAM are changed in the hypervisor. To enlarge the disk, grow the virtual disk while the machine is powered off, then choose items 9 and 5 in the console menu. Before the first boot, growing the disk is enough.