Skip to content

If no package in the catalogue covers your application, you write the installation script yourselves in PowerShell, bash or Python and upload it as a custom agent. sslbrain issues and renews the certificate as usual, and your script installs it.

  • An in-house or less common application reads its certificate from a file, a keystore or the Windows certificate store, and no package in the catalogue knows it.
  • The application must be restarted or given a command after the certificate is replaced, which the catalogue’s packages do not do.
  • The server has a service agent.

A custom agent always runs on the target server. A system that can only be reached through an API from the appliance cannot be covered by a custom agent.

  1. Find out where the application reads the certificate, in which format, and how it is made to load it again.

  2. Write agent.yml and the script. Start from the example for Windows or Linux, and choose the format the application needs with cert_format (variables).

  3. Test the script by hand on a test server with a test certificate before uploading it.

  4. Upload the agent under Agents › Catalogue › Custom agents (upload a custom agent). This needs the Owner role.

  5. Create the rule as in step 8. In the Services step, choose the server through a service on it (choose the services):

    • Windows server with a service agent: choose one of the services discovery has found on the server, such as IIS or RDP. If discovery has found none, the server cannot be chosen in a rule.

    Services cannot be added by hand.

  6. In the Summary step, add your custom agent under Agent chain for … with Add agent. When the service has an agent chain, sslbrain runs the agents in the chain instead of the service’s own package.

A service agent does not run custom agents with its default setting. On every Windows server that is to run your script, set the agent’s script policy to 31, either with the MSI property SCRIPTPOLICY=31 at installation or with Group Policy, which also reaches servers added to the same OU later. The procedure is in The service agent’s script policy.

The appliance signs your custom agent with its own key when it is uploaded, and the service agents trust that key for custom agents. A service agent does not run a script whose signature does not match, so a change to the script means uploading a new version. See Signing.

Run the rule and check that the server delivers the certificate, as described in step 8. If the run fails, the script’s output is on the installation under Deployment › Runs. See also Deployment fails.