Support and diagnostics
Copy link to the page “Support and diagnostics”FairSSL has no access to the appliance unless you open temporary SSH from the console. What support gets, you send yourself: a support bundle, continuous diagnostics, an approved support partner, or SSH for 24 hours.
Contact FairSSL support at info@fairssl.dk. The address is also shown under Maintenance and support › Support.
Support bundle
Copy link to the section “Support bundle”A support bundle is a JSON file with what support needs to find a fault. It is under Maintenance and support › Support, on the Support bundle card. Only administrators can download or send it.
-
Open Maintenance and support › Support.
-
Click Download support bundle to download the file and look through it first. It is named
sslbrain-debug-<date>-<time>.json. -
Click Send to sslbrain Cloud and confirm with Yes, send to sslbrain Cloud to send it to FairSSL. This requires the appliance to be connected to sslbrain Cloud.
-
Tell support what is wrong. The bundle’s reference is shown under Support bundles sent.
The bundle is sent only when someone clicks the button, never on its own. Support bundles sent shows the last 20 with status, reference, size, SHA-256, a summary of the contents, and who sent them.
The bundle contains: system information, database migration status, the queue, open orders, storage use, recent deployments with the agents’ output, the stages of agent tasks, rule runs, agent versions, the last 100 lines of the application log, and every setting.
Removed before download and sending: known secret values, encrypted settings (shown as [ENCRYPTED]), settings with names such as password, secret, key, api_token and hmac (shown as [REDACTED]), and text that looks like passwords, tokens, private keys, Bearer and Basic headers, and connection strings.
Support partner
Copy link to the section “Support partner”A support partner is an IT partner who helps you with sslbrain. When you approve the partner, they become the account’s support contact in sslbrain Cloud and can pass your cases on to FairSSL. The partner gets no access to the appliance.
-
Get an invite code from the partner.
-
Open Maintenance and support › Support, the Support partner tab.
-
Enter the code in Invite code and choose an expiry date. It must be after today and at most 10 years ahead.
-
Click Approve.
The page then shows the partner’s name, email and phone, when the approval was given, and when it expires. Revoke access cancels the approval in sslbrain Cloud and on the appliance. Everyone can see the tab; only administrators can approve and revoke.
Diagnostics
Copy link to the section “Diagnostics”With diagnostics switched on, the appliance continuously sends selected information to FairSSL, so support can see a fault without asking you for a bundle. Diagnostics are off until an administrator switches them on under Maintenance and support › Diagnostics with the switch Share diagnostics with FairSSL.
The checkbox Share diagnostics with FairSSL continuously in step 4 of first-time setup is the same switch. If it was ticked, every section is shared.
You choose which sections are shared:
| Section | Contents |
|---|---|
| Application log | New lines from the appliance’s own log and the process logs, from the moment diagnostics are switched on |
| Service agent runs | Tasks sent to service agents: type, status, times, and the agent’s hostname, OS version and version |
| Push agent runs | Deployments without a service agent: agent and version, endpoint, action, status, exit code and duration |
| Error log | Only the error lines from the same logs |
| Certificate metadata | Name, SAN, issuer, serial number, validity, key type and fingerprint. Never private keys |
| Certificate sources | Which sources are set up, and how, without passwords and API keys |
| Server inventory | Server name, hostname, IP address, operating system and connection status |
| Automation | The rules’ strategy, maintenance window, and whether renewed certificates are deployed automatically |
| Appliance health | Memory, CPU and disk hour by hour, start-ups, upgrades, and processes that have crashed. Only numbers, versions and process names: no hostnames, domains, IP addresses or certificates |
While diagnostics are on:
- The chosen sections are sent to sslbrain Cloud about every 15 minutes, signed and over HTTPS.
- Passwords, tokens, API keys and private keys are removed on the appliance before anything is sent.
- The appliance logs at debug level for as long as the application log is shared.
- FairSSL deletes the data it receives after 30 days.
- FairSSL cannot ask for more than the switch allows.
Switching diagnostics off takes effect at once: nothing more is sent, anything waiting is deleted, and sslbrain Cloud is told.
Temporary SSH for support
Copy link to the section “Temporary SSH for support”On the virtual appliance (OVA and qcow2) you can open SSH for 24 hours so FairSSL support can log in and help. An installation with Docker does not have this option.
-
Open the virtual machine’s console in the hypervisor.
-
Choose 9 Danger zone, then 2 Temporary SSH for support.
-
Answer
yesto “Open temporary SSH for 24 hours?”. -
Give support the appliance’s address. It is shown under 1 Status. Support must be able to reach the address on port 22 or 10022.
While SSH is open:
- it listens on ports 22 and 10022;
- it accepts only the FairSSL support keys built into the image, and never a password;
- support logs in as root.
SSH closes itself after 24 hours, also if the machine is restarted in the meantime; a timer checks every 5 minutes. Close it early from the same screen, which also removes the keys again.
SSH is off by default and can be opened neither remotely nor from the web interface. SSH sessions are recorded in the operating system’s journal.
Appliance and licence
Copy link to the section “Appliance and licence”System › Appliance and licence has three tabs:
| Tab | Who | Shows |
|---|---|---|
| Overview | Everyone | The licence, the Audit log card, Maintenance window, and the appliance’s hostname, version, connection to sslbrain Cloud, last heartbeat, installation date and identity |
| System | Administrators | Status, Restart, Stop sslbrain and Recent activity |
| Licence and units | Administrators | Opens Licences and units in sslbrain Cloud, see sslbrain Cloud |
The licence on Overview shows the tier (Free, Basic, Professional or Enterprise, in every language), servers and users used against included, custom agents, expiry date, automatic renewal, when the licence was last received, and the licence’s features.
Restart restarts sslbrain. The page reconnects by itself afterwards. Stop sslbrain stops sslbrain, but not the operating system.
Recent activity shows the last 50 system actions.
Under Maintenance and support › Support there is a System card with version, database and its size, the number of servers, certificates, agents and sources, uptime, last update check, and licence.