Keep an eye on your certificates
Copy link to the page “Keep an eye on your certificates”sslbrain shows status on Overview and under Monitoring, but only sends a message once you have created a channel and an alert rule. Create a channel under Monitoring › Channels and at least one rule under Monitoring › Alert rules before you rely on anyone hearing when something goes wrong.
Overview of certificates and servers
Copy link to the section “Overview of certificates and servers”Overview is the first item under Daily in the menu. The number next to the menu item (for example “4 need action”) is the count of critical actions and warnings under Actions on the page.
Five cards sit at the top. They count only certificates that sslbrain manages:
| Card | What it shows |
|---|---|
| Managed by sslbrain | Every certificate sslbrain manages. “healthy” are those with more than 30 days left. |
| Expiring soon | Certificates that expire within 30 days. The card turns critical when one of them expires within 7 days (for example “2 within 7 days”). |
| Expired | Expired certificates that are still in use. |
| Servers online | Servers sslbrain can reach, out of all servers. |
| Deployments | The latest 10 deployments. |
Below the cards is the number of certificates found on your servers that sslbrain does not manage, with links to Certificates › Found on servers and Certificates › Expired. See Find the certificates you already have.
The rest of the page:
- Coverage has four figures: With automation (servers with a service in a rule), Without automation, Inventory collected and Awaiting processing (discovered servers sslbrain does not manage yet).
- Expiring certificates lists up to 50 managed certificates that expire within 30 days or expired within the last 30, soonest first.
- Actions is the list of things that need action. An expired certificate and a certificate with 7 days or fewer left are critical; a certificate with 30 days or fewer left is a warning. The list also has items about the appliance’s own TLS certificate, disk space, the licence, servers, deployments, Auto-DNS and the agent catalogue. Some items can be dismissed with ×. Certificate items cannot.
- Getting started is a checklist of the first steps after setup. It disappears once every item is done.
- Servers shows the latest 20 servers and Recent activity the latest 10 deployments.
The page can also show a banner. Emergency access active means someone is signed in with the 12 backup words, see Security. ”… of your … servers are deactivated because the licence covers …” means the licence does not cover every server, see When something does not work.
Monitoring › Alerts shows what needs action now. Alerts are not acknowledged here. Messages go out through alert rules and channels, described below.
At the top are Certificates, Needs attention, Agents online and Deployments (24h). The Active problems list is in this order:
- Expired certificates.
- Certificates in a critical state.
- Deployments that failed in the last 7 days (up to 10).
- Agents that have not checked in for 15 minutes (“The agent on … is offline”), and servers sslbrain cannot reach (”… is not responding”).
- Certificates with a warning.
The tabs Certificates, Agents, Deployments and Timeline show the detail. Deployments and Timeline show the latest 50.
This page counts every certificate, including those only found on your servers. It grades a certificate by its total validity:
| Certificate validity | Warning | Critical |
|---|---|---|
| Over 90 days | 28 days left | 7 days left |
| 11 to 90 days | Under 26.67 % of the validity left | Under 10 % left |
| 10 days or less | Under 47.5 % left | Under 16.67 % left |
Overview counts only managed certificates and uses 30 and 7 days, so the figures on the two pages can differ.
Alert rules
Copy link to the section “Alert rules”An alert rule sends a message to one channel when a given event happens. Without a channel the page shows “Create a notification channel first so alert rules have somewhere to send.” Create the channel first, see Channels.
-
Open Monitoring › Alert rules. The page is called Alert rules.
-
Click New alert rule.
-
Fill in the fields:
Field Content Name A name you will recognise the rule by. Event What the rule reacts to, see the table below. Threshold (days) Used by Certificate expiring: days before expiry, from 1 to 365. Shown on the rule as, for example, “30 days before expiry”. Channel The channel the message is sent to. -
Click Save.
A rule is on once it is saved. Each rule has a switch that turns it off and on, and the buttons Edit and Delete. Operator and the roles above it can create and edit rules. Only an Administrator can delete them.
| Event | Sent when |
|---|---|
| Certificate expiring | A certificate has fewer days left than the threshold. |
| Certificate expired | A certificate has expired. |
| Deployment failed | A deployment to a server failed within the last 24 hours. |
| Renewal failed | An automatic renewal failed within the last 24 hours, or a Windows CA source stopped after 3 failures in a row. |
| Connection lost | sslbrain has not been able to reach a server for more than 2 hours. |
| Agent stale | A service agent has not checked in for more than 48 hours. |
| Certificate mismatch | A deployed certificate does not cover the hostname the binding uses. |
| Unknown certificate discovered | A TLS port seen within the last 24 hours presents a certificate sslbrain does not know. |
| Policy violation | There are open policy findings, a 1024-bit RSA key, or a self-signed certificate in use. |
Rules are evaluated every hour. Everything one rule finds in a run goes to the channel as a single message.
A channel is a recipient of messages: an e-mail address or a webhook. The channel’s settings are stored encrypted in the appliance’s vault.
-
Open Monitoring › Channels. The page is called Notification channels.
-
Under Create a new channel, choose a Channel type. Which types you can choose depends on the licence, see Channels by licence.
-
Enter a Channel name.
-
Fill in the fields under Settings for the channel type. The appliance shows these field names in Danish:
Channel type Fields E-mail (Cloud) Modtager E-mail (SMTP) Modtager, SMTP-server, Port (default 587), Brugernavn, Adgangskode, Kryptering (tls, ssl or none), Afsenderadresse, Afsendernavn Webhook Webhook URL -
Click Create channel. The channel then appears under Existing channels and can be chosen in an alert rule.
A channel cannot be edited on the page. To change an address, create a new channel and select it in the alert rules. History next to the channel shows who created and changed it.
E-mail (Cloud): The Modtager field must be filled in, but it is not used. The recipients are the ones listed in sslbrain Cloud under Notifications (Email recipients, up to 10 addresses). If the list is empty, messages go to the account owner.
Webhook sends an HTTP POST with JSON to the address:
{"text": "<subject>\n<message>", "username": "sslbrain"}The appliance waits at most 15 seconds for a response. The address must be reachable from the appliance.
Channels by licence
Copy link to the section “Channels by licence”| Channel type | Licence | Sent | Requirement |
|---|---|---|---|
| E-mail (Cloud) | Free and up | Through sslbrain Cloud | The appliance is connected to sslbrain Cloud |
| E-mail (SMTP) | Basic and up | Directly from the appliance | An SMTP server the appliance can reach |
| Webhook | Basic and up | Directly from the appliance | An address the appliance can reach |
E-mail (SMTP) and Webhook are also sent when the appliance cannot reach sslbrain Cloud. Choose one of them if alerts must get through during an outage between the appliance and sslbrain Cloud.
A channel type the licence does not include is listed under Unavailable channel types with the text “Requires … tier”, for example “Requires basic tier”. The appliance writes the licence name in lower case: free, basic, professional, enterprise. The licence is changed in sslbrain Cloud, see sslbrain Cloud.
Expired and replaced certificates
Copy link to the section “Expired and replaced certificates”Under Certificates there are two tabs for certificates that are no longer in use:
- Certificates › Expired lists expired certificates that no profile manages and that no newer certificate has replaced. These are usually certificates sslbrain found on your servers. By default it shows those that expired within the last 90 days. “Also show the … that expired more than … days ago” shows the rest. They never become items under Actions.
- Certificates › Replaced lists certificates that a newer certificate has superseded: either a certificate marked as its renewal, or a newer one with the same CN and issuer. They never count towards Expiring soon.
Both tabs show 50 rows per page. Certificates on discovered TLS ports are checked again every night at 04:00, see Find the certificates you already have.
Infrastructure map
Copy link to the section “Infrastructure map”Servers › Infrastructure map (the page is called Infrastructure) shows the chain from certificate source to service in six columns: Sources, Certificate Profiles, Certificates, Deploy rules, Servers & services and Deployed / status.
- The map is built from the links sslbrain has recorded. A missing link is drawn as missing.
- Broken chains and warnings lists the faults with a code, for example
profile_without_source(a profile without a source),certificate_without_rule(a certificate without a rule),deployment_failedandserver_unreachable. - Discovered certificates that nothing uses are grouped into one node.
- Show chain shows the chain for one certificate only.