Skip to content

The appliance, its modules, the agent packages and the service agents on your servers are updated separately. All of it is controlled under Maintenance and support › Updates, which only administrators see. Every version is signed by FairSSL, and the signature is checked before the version is installed.

The appliance asks sslbrain Cloud for a newer version every 4 hours. If the Appliance updates switch is on, a newer signed version is installed automatically, see The four automation switches. To update it yourself:

  1. Take a backup, see Save a backup. The appliance does not take a backup of its own before an update.

  2. Open Maintenance and support › Updates and click Check now. The page shows Installed version, Latest available version and the version’s release notes.

  3. Check that the page says “This release is signed. The signature is checked again before it is installed.” If it says “This release is not signed yet and cannot be installed.”, wait and click Check now later.

  4. Click Update now. Confirm “Update from … to …?” with Confirm update.

  5. The page says “The update is queued and starts within a minute.” The web interface is unavailable while the new version starts.

An update stops the appliance, downloads the new version, checks the signature, starts it and waits for it to respond correctly. If any of these steps fails, the appliance starts again on the version it had. Certificates on your servers are not affected by an update.

The appliance can only be updated to the current signed version the check has found. The check sends nothing to sslbrain Cloud except the appliance’s current version. It can be paused under Deployment › Scheduled in the row Opdateringstjek (brain + agenter), which the appliance shows in Danish.

After every start the appliance compares its version with the one the update should have produced, and shows the result under Last update:

ResultMeaning
CompletedThe appliance runs the new version.
Aborted, the version did not changeThe update did not complete. The appliance runs the version it had.
Completed, but with a different version than expectedThe appliance runs a different version from the one chosen.
The version was changed outside the appliance’s own updateThe version was changed directly on the host, not from the web interface or the console.

Update log shows every attempt with its outcome and reason, for example “Failed: the signature could not be verified”. What to do about each reason is in When something does not work.

The Host updates card controls when fixes to the virtual machine itself are applied (OVA and qcow2). The fixes come with the signed updates and cover the console menu, logins, SSH, hardening and the controller:

OptionWhat happens
Security fixes only, automatically (default)Security fixes run with the next update. Everything else waits for your approval.
Automatically in the maintenance windowEverything runs automatically while the appliance’s maintenance window is open.
Manual onlyNothing runs until you have read and approved it, security fixes included.

Ubuntu on the virtual appliance installs security updates by itself every day. If one of them needs a restart, the machine restarts at 03:00 and the appliance is back within about a minute. If the appliance runs in Docker on your own Linux server, you update the host yourself.

Updates › Automation has four switches. They decide what the appliance downloads, installs and approves by itself. When you save, the work starts within a few seconds.

SwitchWhat it doesWhen
Appliance updatesInstalls a newer signed version of the appliance.The check runs every 4 hours.
ModulesDownloads licence modules and keeps them up to date. A download does not activate a module, see Modules.Every night at 03:30.
Agent packagesDownloads new versions of agent definitions and service agent packages.Every night at 03:15.
Automatic agent approvalApproves a new agent that checks in with a valid key from this appliance.When the agent checks in.

Agent packages cannot be switched off while Approve new versions automatically (recommended) is on under Agents › Settings, see What sslbrain can install on.

With Automatic agent approval off, new agents wait for an administrator. An agent installed with an install code waits under Agents › Install codes. An agent installed without an install code waits under Servers. See Connect servers.

The choice made during setup (Auto or Manual) set the switches’ starting value: all four on or all four off. From then on the switches decide. The card shows Automatic, Manual or Custom depending on how they are set. Policy and audit › Operation mode shows the starting choice and cannot be changed, see Policy and audit.

Two things have no switch here:

  • Certificate renewal always runs, every 3 hours, see First certificate on a server.
  • Deployment after renewal is chosen on each rule with Auto-deploy on certificate renewal.

If the web interface does not respond, the virtual appliance can be updated from the console in the hypervisor. The console menu is in English. An appliance in Docker has no console menu.

  1. Open the machine’s console in the hypervisor. The menu is on the screen. Press Enter if it has not been drawn.

  2. Choose 6 Update to the latest version. This is the same update as from the web interface, with the same signature check.

  3. The screen shows working... mm:ss while the update runs, and ends with WORKED. or FAILED (exit N). Pressing Enter lets the update carry on in the background.

If the update fails, 4 View logs and then 2 The controller: updates, restarts, signature checks show why. If the appliance software is broken, 9 Danger zone and then 6 Reinstall the appliance software (data kept) download the running version again and start it afresh. Certificates, settings, accounts and the database are kept. See Console menu.

The Service agent updates card on the same page moves the service agents on your servers to a version from FairSSL’s signed catalogue. The server checks FairSSL’s signature itself before it installs. If the new version does not check in within 10 minutes, the server reinstalls the version it had.

The card has three options: Automatic (recommended), Manual and Off. Only an Owner can change it. Which versions can be updated, and how to update one server or many, is in Keep service agents up to date.