sslbrain Cloud
Copy link to the page “sslbrain Cloud”In sslbrain Cloud you activate the appliance, choose a licence, buy units and give colleagues access. Each appliance fetches its licence from there. Certificates, private keys and settings are kept on the appliance, not in sslbrain Cloud.
Create an account at sslbrain.com/cloud/register with email and password, or with GitHub, Google or Microsoft. The email address must be confirmed before the account can be used. Sign in at sslbrain.com/cloud/login.
Two-factor authentication is switched on under Two-Factor Auth. The account can remember trusted devices.
The menu in sslbrain Cloud:
| Group | Items |
|---|---|
| Daily | Overview, Certificates, Appliances |
| Certificate setup | The pages for setting up certificates |
| Licence and billing | Licences and units, Invoicing |
| Account and team | Team, Notifications, DPA, Audit log |
| At the bottom | Downloads and requirements, Contact and help |
Notifications lists the email addresses (at most 10) that alerts from the appliance’s E-mail (Cloud) channel are sent to. If none are listed, they go to the account owner. See Keep an eye on your certificates.
Roles in sslbrain Cloud
Copy link to the section “Roles in sslbrain Cloud”| Role | Can |
|---|---|
| Owner | Everything |
| Administrator | The same as Owner, except renaming the Auto-DNS name |
| Operator | Day-to-day work and certificate setup. Can see licences and the team, but nothing to do with payment |
| Viewer | View, not change |
| Billing | Licences, purchases, invoices, the data processing agreement and payment events in the Audit log. No access to appliances |
The role in sslbrain Cloud also decides the role on the appliance when you sign in with sslbrain Cloud, see Users and sign-in.
Appliances
Copy link to the section “Appliances”Appliances shows every appliance activated with the account: hostname, tier, licence, version, and when it last contacted sslbrain Cloud. An appliance appears in the list the moment someone signs in to it with the account and chooses a licence.
Click an appliance to see:
- Overview: appliance id, IP address and registration date, and a Display name the appliance is shown with throughout the portal;
- Licence: the licence history, and Switch licence to another licence the account holds. The appliance keeps its identity, its data and its certificates;
- Certificates: the certificates sslbrain Cloud has issued to the appliance;
- Auto-DNS names: the names the appliance uses for CNAME delegation;
- Danger zone: releasing the licence, see Move the licence to another appliance.
Only Owner and Administrator can switch and release licences.
Downloads and requirements
Copy link to the section “Downloads and requirements”Downloads and requirements at the bottom of the menu has the files for a new appliance and its requirements. Every role except Billing can open the page. The account must first have accepted the licence terms and the data processing agreement.
| File | For |
|---|---|
| OVA | VMware and other hypervisors that import OVF |
| qcow2 | KVM, libvirt and Proxmox |
docker-compose.yml | Docker on your own Linux server |
The compose file only starts the appliance. It does not install the host controller that carries out the updates, restarts and restores you start from the web interface. For Docker, get the installation script from FairSSL instead, which also installs the controller. The appliance then answers on port 8443.
The OVA and qcow2 files are listed with version, size and SHA-256. The VM image version is the date the image was built. The virtual machine installs the newest signed version of sslbrain the first time it starts. The OVA and qcow2 files are not signed; the appliance image they fetch at start-up is, see Security.
Your licences shows the licences a new appliance can take.
Virtual appliance requirements: 2 vCPU, 4 GB RAM and 40 GB disk (thin provisioned).
Docker requirements: Docker 24.0 or newer, Docker Compose v2, 4 GB RAM, 20 GB disk space, and network access to the CAs’ ACME endpoints.
Firewall:
- Outbound HTTPS (443) to
registry.sslbrain.com,cloud.sslbrain.comandacme.sslbrain.com. - The virtual appliance also needs outbound HTTP (80) to
archive.ubuntu.comandsecurity.ubuntu.comfor operating system security updates. - No inbound ports from the internet.
The full list of ports, including those on your own network, is under Security.
Licences and units
Copy link to the section “Licences and units”A licence belongs to one appliance and sets how much it can manage. The appliance knows four tiers: Free, Basic, Professional and Enterprise. First-time setup calls Free “Community”.
| Limit | Free | Basic | Professional | Enterprise |
|---|---|---|---|---|
| Servers | 5 | 25 | 250 | Unlimited |
| Rules | 10 | 50 | 500 | Unlimited |
| Logins | 1 | 3 | 10 | Unlimited |
| Domains per account | 10 | Unlimited | Unlimited | Unlimited |
| Names per certificate | 100 | Unlimited | Unlimited | Unlimited |
| Certificate profiles | 1 | 3 | Unlimited | Unlimited |
| Custom agents | 1 | 3 | Unlimited | Unlimited |
Features that need a particular tier:
| Feature | From |
|---|---|
| Alerts by E-mail (SMTP) and Webhook | Basic |
| Certificate upload | Basic |
| Service agents via sslbrain Cloud | Professional |
| Maintenance windows | Professional |
| Audit log export | Professional |
| Windows CA | Enterprise, plus an add-on that FairSSL switches on for the licence |
How the limits work:
- Servers: the licence covers the oldest servers up to the limit. Servers beyond the limit are deactivated, and the appliance shows next to them that they lack a licence. A new server is never refused.
- Rules: on Free the 11th rule is refused when it is created. A paused rule counts; the appliance’s own rule does not. Nothing that already exists stops.
- If a paid licence expires, the appliance falls back to Free.
Every account has a Free licence from the start. A paid licence that expires becomes a Free licence on the appliance it was on, and cannot be used on another.
The appliance’s own page Appliance and licence › Licence and units opens Licences and units in sslbrain Cloud.
Units pay for the paid certificates sslbrain Cloud issues. One unit equals one standard DV certificate. Other products cost more units, depending on the product and the number of names.
- Units are deducted when sslbrain Cloud issues a paid certificate, and are held by open orders.
- The balance plus the credit limit FairSSL has set must cover an order.
- Buy units creates an invoice straight away. It is paid by card or bank transfer.
- Owner, Administrator and Billing can buy.
- The account receives an email when the balance is low.
Which certificates a profile can fetch is described under Choose where certificates come from.
Under Team you give colleagues access to one or more appliances.
-
Open Team and find Add a person.
-
Enter the email address, choose the appliances the person should have access to, and choose the role: Administrator, Operator or Viewer. Choose Billing if the person should only see licences and invoices; no appliance is chosen then.
-
Click Add.
If the person is already a member of the account, they get access straight away. Otherwise sslbrain Cloud sends an invitation that is valid for 7 days. The invitation can be resent or revoked.
- The Owner role cannot be assigned.
- Nobody can change their own role.
- Owner and Administrator manage the team. Operator can see it.
The team page shows, for example, “3 of 10 logins”. sslbrain Cloud counts every user on the account plus pending invitations, across all the account’s appliances. The appliance counts its own logins, see Users and sign-in.
Move the licence to another appliance
Copy link to the section “Move the licence to another appliance”A licence is moved by releasing it in sslbrain Cloud and taking it into use on the new appliance. Data does not move with the licence: certificates, private keys, service agents and settings stay on the appliance you are leaving.
-
Open Appliances in sslbrain Cloud and click the appliance you are leaving.
-
Under Danger zone, on the card Move this licence to another machine, click Release the licence. Type
releaseto confirm, and click Release it. Only Owner and Administrator can do this. The appliance you are leaving keeps running until the new one takes over the licence. -
Set up the new appliance as in First-time setup. When you choose a licence, setup offers Move the licence from followed by the name of the appliance you are leaving. Choose it.
-
Set up the rest as in steps 3 to 8, starting from A name and certificate for the appliance.
The moment the new appliance takes over the licence, the one you are leaving is retired. It shows This installation has been retired and no longer serves anything. Its local data can still be opened with the 12 backup words.
When it makes sense to move, and how to restore on the same machine, is described under Move or restore the appliance.
If you only need to reinstall the appliance software on the same virtual machine, use 6 Reinstall the appliance software in the console menu. Data is kept, and the licence does not need to be moved.