Skip to content

A module is a signed add-on to the appliance that your licence gives access to. Modules are downloaded from sslbrain Cloud and switched on under Modules, which only administrators can see.

The Modules page shows the modules that are on the appliance. sslbrain Cloud offers the modules the licence tier gives. An add-on (for example Windows CA) is offered once FairSSL has switched it on for the licence.

  1. Open Modules.

  2. Click Download licensed modules and updates. The appliance downloads the modules the licence gives and checks their signatures. A downloaded module is switched off.

  3. Click Aktiver on the module you want to use. The button is in Danish in the English interface too. The module now shows Activation pending.

  4. Click Restart and apply. The appliance restarts the application (not the virtual machine), and the module is loaded. The web interface is gone for a moment.

A module is switched off the same way: Deaktiver, then Restart and apply.

Upload modul takes a signed ZIP file of at most 50 MB. A module with an invalid signature or damaged files is not imported.

A module the licence does not cover shows Ikke i licens and cannot be switched on.

Automatic updates: if the Modules switch is on under Updates › Automation, the appliance downloads module updates every night at 03:30. A download never switches a module on. See Keep sslbrain up to date.

The Windows CA (AD CS) module lets the appliance order certificates from your own Microsoft CA (Active Directory Certificate Services) through a service agent on a Windows server in the domain.

It requires:

  • the Enterprise licence;
  • the Windows CA add-on, which FairSSL switches on for the licence. Contact FairSSL to get it;
  • an approved service agent on a Windows server that can reach the CA.

Once the module is downloaded, switched on and loaded as described above, the CA is set up as a source under Sources › Sources with the type Windows CA. If the module is not loaded, the page says, in Danish: “Windows CA-modulet er ikke indlæst på denne appliance. Aktivér det under Moduler og genstart.”

The full procedure, with permissions on the template and a check of the first certificate, is under Internal certificates from Windows CA.

A maintenance window is the days and times when sslbrain may install certificates on the servers. Without a window, installation can happen at any time, which is the default. Windows require the Professional or Enterprise licence.

There are two levels:

LevelWhereApplies to
The whole applianceAppliance and licence › Overview, the Maintenance window cardAll rules that do not have their own window
One ruleThe rule wizard, the Maintenance window fieldOnly that rule. It ignores the appliance’s window

To set the window for the whole appliance:

  1. Open System › Appliance and licence › Overview.

  2. Choose the days, and enter the start and end in the Maintenance window card.

  3. Save.

A window that ends before it starts runs past midnight and belongs to the day it opens. “Wednesday 22:00 to 04:00” is Wednesday night: 23:00 on Wednesday and 02:00 on Thursday are inside it, 23:00 on Thursday is not.

Remove window removes the window again. It needs no licence. A saved window still applies after the licence is downgraded, until you remove it.

Outside the window, the rule’s run waits until the window opens, and the certificate shows “waiting for window” next to the rule. Alerts are sent regardless of the window.

The Maintenance windows module in the list of modules is not needed for windows. The licence decides whether a window can be saved. See First certificate on a server for the rule’s own window.