Skip to content

A service agent that cannot reach the appliance directly can send its messages through sslbrain Cloud. The agent and the appliance both connect only outbound to sslbrain Cloud, so you do not open any port into the appliance or into the server.

  • Servers in branch offices or other sites with no VPN to the network the appliance is on.
  • Servers at a hosting provider or in a cloud.
  • Servers behind a firewall that may not open for traffic to the appliance.
  • Servers that normally reach the appliance directly but must carry on when the direct route is down.

The agent uses sslbrain Cloud when no direct address answers. With sslbrain Cloud last in the list, the agent uses the direct route for as long as it works.

Messages between agent and appliance are signed by the sender (ES384) and encrypted to the recipient (JWE with ECDH-ES and AES-256-GCM). The appliance’s keys are P-384. sslbrain Cloud forwards the messages and can neither read them, change them nor create new ones. sslbrain Cloud can delay or drop a message, but it cannot make the agent carry out anything.

sslbrain Cloud sees this metadata:

  • the installation’s ID and the IDs of the agents’ mailboxes;
  • the size of each message and when it was sent;
  • the agents’ public IP addresses.

sslbrain Cloud knows the agent by a random pseudonym and stores only a SHA-256 of the agent’s access token. The install code carries the appliance’s fingerprint, so the agent trusts only your appliance, also when the messages go through sslbrain Cloud. What else sslbrain Cloud sees from the appliance: Security.

  • A Professional or Enterprise licence.
  • An appliance connected to sslbrain Cloud.
  • A service agent installed with an install code: the Windows agent from version 1.3.3 (Install with an install code). An agent installed with the registration token cannot use sslbrain Cloud until it has moved to an install code (Agents installed without an install code).
  • Outbound HTTPS from the server to cloud.sslbrain.com on port 443.

The appliance collects messages from sslbrain Cloud every 15 seconds. A task through sslbrain Cloud therefore takes a little longer than a direct one.

If the licence or the connection to sslbrain Cloud is missing, Agents › Connection says so under the switch. The choice is saved and takes effect once both are in place.

  1. Open Agents › Connection.

  2. Turn on Agent traffic through Cloud under Addresses, and save. sslbrain Cloud is now last in the list for every agent installed with an install code.

  3. Create an install code for the server under Agents › Install codes. With the switch on, cloud is last under Addresses on the code, for example https://sslbrain.firma.dk,cloud.

  4. Install the agent on the server with the code (Install with an install code).

  5. Approve the machine under Agents › Install codes.

If the server can never reach the appliance directly, the code can have cloud as its only address. The agent then also fetches its first configuration through sslbrain Cloud.

The agent uses the first address in the list that works.

  • If an address fails three times in a row (Switch address after failures in a row), the agent moves on to the next address.
  • After 1800 seconds it tries the first address again (Retry the first address after).
  • Replies from the appliance go back the same way the message came.
  • If an agent does not collect a message directly within two check-in intervals, the appliance also places it in the agent’s mailbox in sslbrain Cloud.

The values are changed under Agents › Connection (Retries and switching address).

The recommendation is the appliance’s direct address first and cloud last. Traffic then goes through sslbrain Cloud only when the direct route is down.

  1. Open the server under Servers.

  2. In the Service agent panel, open Settings for this agent.

  3. Enter the agent’s list in Addresses in priority order (comma-separated, cloud for sslbrain Cloud). The list may contain only the direct addresses from Agents › Connection and cloud. Remove cloud to keep the agent out of sslbrain Cloud.

  4. Save. The agent gets the list the next time it checks in.

An agent installed without cloud in its list has opted out of sslbrain Cloud. It does not get sslbrain Cloud back by itself. An administrator can click Turn Cloud on again for this agent on the server’s page, and the choice is recorded in the audit log.

If a server must never contact sslbrain Cloud, whatever the appliance sends, install the agent with CLOUD=deny (MSI properties). It can also be set by GPO as CloudDeny under HKLM\SOFTWARE\Policies\SSLBrain. Agents › Install codes shows it as Blocked locally on the machine.

  1. Open Agents › Connection.

  2. Turn off Agent traffic through Cloud.

  3. Read the list These agents have reached the appliance only through Cloud. They lose their connection if they cannot reach the appliance directly.

  4. Save.

The agents first receive a configuration without sslbrain Cloud. Their mailbox in sslbrain Cloud is removed once they have taken that configuration into use, or after 30 days for an agent that cannot reach the appliance directly.

Updating agents that reach the appliance only through sslbrain Cloud

Copy link to the section “Updating agents that reach the appliance only through sslbrain Cloud”

A Windows agent fetches updates from the first direct address in its list. A Windows agent that can reach the appliance only through sslbrain Cloud therefore cannot be updated from the appliance. Update it with a new MSI file on the server (Agents that cannot be updated from the appliance).

The Service agent panel on the server’s page shows:

  • Addresses in use with cloud in the list;
  • Cloud: Allowed;
  • Cloud mailbox: Ready;
  • Last reached: Through Cloud when the agent last came through sslbrain Cloud, and Directly when it came directly.
  • Approval gives “The agent can only be reached through sslbrain Cloud, and Cloud did not give it a mailbox just now”: try again shortly. The machine is still waiting for approval.
  • Cloud mailbox shows “Cloud refused it; tried again in an hour”: the appliance retries by itself. Check the licence and the appliance’s connection to sslbrain Cloud.
  • Cloud shows Opted out or Blocked locally on the machine: see One agent with its own addresses.
  • The agent does not check in at all: check that the server can reach cloud.sslbrain.com on port 443, and see A service agent does not check in.