Skip to content

sslbrain shows status on Overview and under Monitoring, but only sends a message once you have created a channel and an alert rule. Create a channel under Monitoring › Channels and at least one rule under Monitoring › Alert rules before you rely on anyone hearing when something goes wrong.

Overview is the first item under Daily in the menu. The number next to the menu item (for example “4 need action”) is the count of critical actions and warnings under Actions on the page.

Five cards sit at the top. They count only certificates that sslbrain manages:

CardWhat it shows
Managed by sslbrainEvery certificate sslbrain manages. “healthy” are those with more than 30 days left.
Expiring soonCertificates that expire within 30 days. The card turns critical when one of them expires within 7 days (for example “2 within 7 days”).
ExpiredExpired certificates that are still in use.
Servers onlineServers sslbrain can reach, out of all servers.
DeploymentsThe latest 10 deployments.

Below the cards is the number of certificates found on your servers that sslbrain does not manage, with links to Certificates › Found on servers and Certificates › Expired. See Find the certificates you already have.

The rest of the page:

  • Coverage has four figures: With automation (servers with a service in a rule), Without automation, Inventory collected and Awaiting processing (discovered servers sslbrain does not manage yet).
  • Expiring certificates lists up to 50 managed certificates that expire within 30 days or expired within the last 30, soonest first.
  • Actions is the list of things that need action. An expired certificate and a certificate with 7 days or fewer left are critical; a certificate with 30 days or fewer left is a warning. The list also has items about the appliance’s own TLS certificate, disk space, the licence, servers, deployments, Auto-DNS and the agent catalogue. Some items can be dismissed with ×. Certificate items cannot.
  • Getting started is a checklist of the first steps after setup. It disappears once every item is done.
  • Servers shows the latest 20 servers and Recent activity the latest 10 deployments.

The page can also show a banner. Emergency access active means someone is signed in with the 12 backup words, see Security. ”… of your … servers are deactivated because the licence covers …” means the licence does not cover every server, see When something does not work.

Monitoring › Alerts shows what needs action now. Alerts are not acknowledged here. Messages go out through alert rules and channels, described below.

At the top are Certificates, Needs attention, Agents online and Deployments (24h). The Active problems list is in this order:

  1. Expired certificates.
  2. Certificates in a critical state.
  3. Deployments that failed in the last 7 days (up to 10).
  4. Agents that have not checked in for 15 minutes (“The agent on … is offline”), and servers sslbrain cannot reach (”… is not responding”).
  5. Certificates with a warning.

The tabs Certificates, Agents, Deployments and Timeline show the detail. Deployments and Timeline show the latest 50.

This page counts every certificate, including those only found on your servers. It grades a certificate by its total validity:

Certificate validityWarningCritical
Over 90 days28 days left7 days left
11 to 90 daysUnder 26.67 % of the validity leftUnder 10 % left
10 days or lessUnder 47.5 % leftUnder 16.67 % left

Overview counts only managed certificates and uses 30 and 7 days, so the figures on the two pages can differ.

An alert rule sends a message to one channel when a given event happens. Without a channel the page shows “Create a notification channel first so alert rules have somewhere to send.” Create the channel first, see Channels.

  1. Open Monitoring › Alert rules. The page is called Alert rules.

  2. Click New alert rule.

  3. Fill in the fields:

    FieldContent
    NameA name you will recognise the rule by.
    EventWhat the rule reacts to, see the table below.
    Threshold (days)Used by Certificate expiring: days before expiry, from 1 to 365. Shown on the rule as, for example, “30 days before expiry”.
    ChannelThe channel the message is sent to.
  4. Click Save.

A rule is on once it is saved. Each rule has a switch that turns it off and on, and the buttons Edit and Delete. Operator and the roles above it can create and edit rules. Only an Administrator can delete them.

EventSent when
Certificate expiringA certificate has fewer days left than the threshold.
Certificate expiredA certificate has expired.
Deployment failedA deployment to a server failed within the last 24 hours.
Renewal failedAn automatic renewal failed within the last 24 hours, or a Windows CA source stopped after 3 failures in a row.
Connection lostsslbrain has not been able to reach a server for more than 2 hours.
Agent staleA service agent has not checked in for more than 48 hours.
Certificate mismatchA deployed certificate does not cover the hostname the binding uses.
Unknown certificate discoveredA TLS port seen within the last 24 hours presents a certificate sslbrain does not know.
Policy violationThere are open policy findings, a 1024-bit RSA key, or a self-signed certificate in use.

Rules are evaluated every hour. Everything one rule finds in a run goes to the channel as a single message.

A channel is a recipient of messages: an e-mail address or a webhook. The channel’s settings are stored encrypted in the appliance’s vault.

  1. Open Monitoring › Channels. The page is called Notification channels.

  2. Under Create a new channel, choose a Channel type. Which types you can choose depends on the licence, see Channels by licence.

  3. Enter a Channel name.

  4. Fill in the fields under Settings for the channel type. The appliance shows these field names in Danish:

    Channel typeFields
    E-mail (Cloud)Modtager
    E-mail (SMTP)Modtager, SMTP-server, Port (default 587), Brugernavn, Adgangskode, Kryptering (tls, ssl or none), Afsenderadresse, Afsendernavn
    WebhookWebhook URL
  5. Click Create channel. The channel then appears under Existing channels and can be chosen in an alert rule.

A channel cannot be edited on the page. To change an address, create a new channel and select it in the alert rules. History next to the channel shows who created and changed it.

E-mail (Cloud): The Modtager field must be filled in, but it is not used. The recipients are the ones listed in sslbrain Cloud under Notifications (Email recipients, up to 10 addresses). If the list is empty, messages go to the account owner.

Webhook sends an HTTP POST with JSON to the address:

{"text": "<subject>\n<message>", "username": "sslbrain"}

The appliance waits at most 15 seconds for a response. The address must be reachable from the appliance.

Channel typeLicenceSentRequirement
E-mail (Cloud)Free and upThrough sslbrain CloudThe appliance is connected to sslbrain Cloud
E-mail (SMTP)Basic and upDirectly from the applianceAn SMTP server the appliance can reach
WebhookBasic and upDirectly from the applianceAn address the appliance can reach

E-mail (SMTP) and Webhook are also sent when the appliance cannot reach sslbrain Cloud. Choose one of them if alerts must get through during an outage between the appliance and sslbrain Cloud.

A channel type the licence does not include is listed under Unavailable channel types with the text “Requires … tier”, for example “Requires basic tier”. The appliance writes the licence name in lower case: free, basic, professional, enterprise. The licence is changed in sslbrain Cloud, see sslbrain Cloud.

Under Certificates there are two tabs for certificates that are no longer in use:

  • Certificates › Expired lists expired certificates that no profile manages and that no newer certificate has replaced. These are usually certificates sslbrain found on your servers. By default it shows those that expired within the last 90 days. “Also show the … that expired more than … days ago” shows the rest. They never become items under Actions.
  • Certificates › Replaced lists certificates that a newer certificate has superseded: either a certificate marked as its renewal, or a newer one with the same CN and issuer. They never count towards Expiring soon.

Both tabs show 50 rows per page. Certificates on discovered TLS ports are checked again every night at 04:00, see Find the certificates you already have.

Servers › Infrastructure map (the page is called Infrastructure) shows the chain from certificate source to service in six columns: Sources, Certificate Profiles, Certificates, Deploy rules, Servers & services and Deployed / status.

  • The map is built from the links sslbrain has recorded. A missing link is drawn as missing.
  • Broken chains and warnings lists the faults with a code, for example profile_without_source (a profile without a source), certificate_without_rule (a certificate without a rule), deployment_failed and server_unreachable.
  • Discovered certificates that nothing uses are grouped into one node.
  • Show chain shows the chain for one certificate only.