Policy and audit
Copy link to the page “Policy and audit”The menu group Policy and audit brings together what decides what the appliance may do on its own, and the log of what it and its users have done.
Operation mode
Copy link to the section “Operation mode”The operation mode is what the appliance does by itself: installing updates, downloading modules and agent packages, and approving new agents. It has no effect on certificate renewal, which always runs.
The operation mode is chosen once, in step 4 of first-time setup, Operation and diagnostics. Nothing is preselected.
| Option | What it switches on |
|---|---|
| Auto | Appliance updates, module updates, agent package downloads and automatic agent approval. The appliance downloads straight away. |
| Manual | None of the four. The agent versions that ship with the appliance are approved in the name of the person who made the choice. |
The checkbox Share diagnostics with FairSSL continuously on the same screen is a separate choice and is not ticked by default, see Support and diagnostics.
After setup, Policy and audit › Operation mode shows only what was chosen and what applies now:
- Start choice during setup and the date of the choice.
- Automation now with the four switches: Appliance updates, Modules, Agent packages and Automatic agent approval. The page shows Automatic, Manual or Custom, depending on how the switches are set.
- Whether the appliance shares diagnostics with FairSSL.
After setup, the four switches are what counts. You change them under Updates › Automation, see Keep sslbrain up to date. The page is for administrators only.
Scripts on the servers
Copy link to the section “Scripts on the servers”Which scripts a service agent runs is decided on the server. The page Policy and audit › Script policy shows a choice under Allowed scripts, but that choice is not sent to the agents. Two things decide what runs:
The agent’s script policy on the server
Copy link to the section “The agent’s script policy on the server”The service agent checks the signature of every script itself before it runs, and runs only the types its script policy allows. The policy is a number made by adding these values:
| Value | Allows |
|---|---|
| 1 | Scripts from FairSSL that read |
| 2 | Scripts from FairSSL that make changes |
| 4 | Community scripts that read |
| 8 | Community scripts that make changes |
| 16 | Custom agents that you have uploaded yourself |
The default is 15. It runs scripts from FairSSL and the community, but not your own custom agents. For a Windows server to run a custom agent, the policy must include 16, for example 31. It is set on the server: add SCRIPTPOLICY=31 to the msiexec command at installation (Windows servers), or set the value ScriptPolicy with a GPO in HKLM\SOFTWARE\Policies\SSLBrain. The appliance cannot change it remotely.
Devices without an agent have no script policy on the device.
Which agent versions the appliance uses
Copy link to the section “Which agent versions the appliance uses”Under Agents › Settings, Download new versions automatically and Approve new versions automatically (recommended) control whether new versions of the agent packages are downloaded and put into use on their own. Automatic approval can only be on while downloading is on. If you switch approval off, the versions running now are approved in your name, and new versions wait under Agents › Catalogue until an administrator approves them. See What sslbrain can install on.
Custom agents are described under Your own scripts and Servers sslbrain does not know.
Domain limit on Free
Copy link to the section “Domain limit on Free”On Free, an sslbrain Cloud account can have certificates for at most 10 registrable domains, across all the account’s appliances, and a certificate can have at most 100 names. A registrable domain is, for example, example.com: www.example.com and mail.example.com count as the same domain. Basic, Professional and Enterprise have no limit.
sslbrain Cloud does the counting when a certificate is ordered. There is no lock period: the number of domains on the account decides whether an order goes through, whatever the page Policy and audit › Domain lock shows.
Audit log
Copy link to the section “Audit log”The audit log is under Policy and audit › Audit log, and every role can see it. It shows every change and every sign-in on the appliance, 50 rows at a time, and can be filtered by action, user, entity type, object ID and time period. Show diff shows what a change did.
The rows are linked in a hash chain, see Audit and compliance. What is logged, how long rows are kept, and how the log is exported (requires Professional or Enterprise) is described under Audit and compliance.