Step 3 of 8
3. A name and certificate for the appliance
Copy link to the page “3. A name and certificate for the appliance”The appliance gets a name, so browsers and service agents can reach it with a certificate they trust. You make the choice in the wizard’s last step, Access and hostname, and can change it afterwards.
The wizard offers three choices. Free my.sslbrain.net hostname is selected by default.
| Choice | Name | Certificate |
|---|---|---|
| Free my.sslbrain.net hostname | <name>.my.sslbrain.net | A trusted certificate, which sslbrain orders as soon as the wizard is finished. There is nothing more for you to do. |
| Own domain | for example sslbrain.example.com | Self-signed, until you have domain validation ready (step 6) and have chosen a certificate profile. |
| Skip | The IP address only | Self-signed. |
The free name
Copy link to the section “The free name”sslbrain Cloud creates a DNS record, <name>.my.sslbrain.net, that points at the appliance’s address on your network.
-
Choose Free my.sslbrain.net hostname.
-
Change the name part if you want something other than the suggestion. It must be 6-10 characters, lowercase letters and digits only, with at least one letter. Hyphens are not allowed. Below the field, the wizard shows the full address.
-
Check IP address for the DNS name. This is the private IPv4 address that clients reach the appliance on (10.x.x.x, 172.16-31.x.x or 192.168.x.x). If the appliance runs in Docker, it is the Docker host’s address, not the container’s.
-
Click Complete setup and go to dashboard.
The name is in public DNS but points at a private address, so it only works from inside your own network. Each sslbrain Cloud account can get three new free names a week. If you change the name later, the new name counts towards the three.
If the appliance answers on a port other than 443, the port must be part of the address, for example https://<name>.my.sslbrain.net:8443.
The appliance’s own certificate
Copy link to the section “The appliance’s own certificate”With the free name, sslbrain creates an ordinary rule that orders and installs the appliance’s certificate. The rule runs straight away.
- The server is the appliance itself. It is listed under Servers with the badge This appliance, does not count towards the licence and cannot be deleted.
- The profile is Default from sslbrain Cloud. sslbrain Cloud orders from Let’s Encrypt and switches to Google Trust Services by itself if Let’s Encrypt fails.
- Domain validation is handled by sslbrain Cloud for names under
my.sslbrain.net. - Renewal works as for every other rule. See Renewal.
If the rule cannot be created during setup, the wizard still completes, with a warning, and the appliance tries again once a day.
Your own name
Copy link to the section “Your own name”A name in your own domain needs two things you set up yourself: a DNS record for the name, and domain validation before a trusted certificate can be issued. In the wizard you only set the name.
-
Choose Own domain and enter the full name, for example
sslbrain.example.com. -
Click Complete setup and go to dashboard. The appliance still uses a self-signed certificate, now with the new name.
-
Create an A record for the name in your DNS, pointing at the appliance’s address.
You choose the trusted certificate once domain validation for the domain is ready with a CNAME delegation or a DNS API credential (step 6):
-
Open Network and DNS › Network, and under Certifikatkilde choose Your own domain with a certificate profile. Choose the profile, for example Default (sslbrain Cloud).
-
Create the record that the Validating the name box shows:
_acme-challenge.sslbrain.example.com CNAME <your Auto-DNS name>If a DNS API credential already covers the zone, the record is not needed. A profile from Windows CA needs no record either.
-
Click Test DNS. The appliance looks up the record and shows whether it was found.
-
Click Gem TLS-kilde.
You can save before the DNS record exists. The appliance then holds off issuing and keeps trying until the record answers.
With Skip, you use the appliance on its IP address with the self-signed certificate, and the browser warns every time. The screen refers to “Settings”. The place is Network and DNS › Network, and that is where you choose a name when you are ready. See Change the name or certificate later.
Logging in after setup
Copy link to the section “Logging in after setup”The wizard logs you in and goes to the dashboard. You log in with your sslbrain Cloud login. Until the appliance has seen your password, you can only log in while sslbrain Cloud can be reached. The appliance stores the password the first time you log in with email and password. Create a local password so you can also get in when sslbrain Cloud is down. See Local password.
Change the name or certificate later
Copy link to the section “Change the name or certificate later”The name and certificate are changed under Network and DNS › Network. The page is headed Network and access.
- Værtsnavn & HTTPS-certifikat: choose Gratis sslbrain-værtsnavn, Eget domænenavn (BYOD) or Kun IP-adresse (Spring over), and click Gem og aktiver værtsnavn.
- HTTPS & Manuel TLS-konfiguration: under Certifikatkilde, choose where the certificate comes from, and click Gem TLS-kilde.
| Choice under Certifikatkilde | What happens |
|---|---|
| Self-signed certificate (default) | The appliance uses its own certificate. The rule for the appliance’s certificate is paused. |
| Manual upload (server.crt + server.key) | You upload a certificate and a private key, which must match. The rule is paused, and sslbrain does not renew the certificate. |
| Free name under .my.sslbrain.net (sslbrain handles validation) | A certificate for the free name. Requires a connection to sslbrain Cloud. The rule runs again. |
| Your own domain with a certificate profile | A certificate for your own name from the chosen profile, as in Your own name. The rule runs again. |
Check that it works
Copy link to the section “Check that it works”- Open
https://<name>.my.sslbrain.net(or your own name) from a machine on the network. The browser shows no warning, and the certificate is issued by Let’s Encrypt or Google Trust Services. - Servers shows a row with the badge This appliance.
- Certificates › Managed by sslbrain shows the appliance’s certificate with the new name.
If you chose Skip, the browser still shows a warning. That is expected.
If it fails
Copy link to the section “If it fails”- The name does not resolve, or the certificate does not arrive: the appliance must have a connection to sslbrain Cloud. See No connection to sslbrain Cloud.
- Your own name is not validated: check the
_acme-challengerecord with Test DNS. See Domain validation fails. - The rule for the appliance’s certificate fails: open the rule under Deployment › Rules and look at the run. See Installation fails.