Skip to content

Everyone who signs in to the appliance has a login with one of four roles. Users are managed under Users and login › Users, which only administrators can see.

The sign-in page has a form for email and password, and two buttons:

On the sign-in pageWhat it does
Email and passwordA local password or your sslbrain Cloud password. A Cloud password is checked by sslbrain Cloud.
Log in with sslbrain CloudSends the browser to sslbrain Cloud. Shown once the appliance has been activated during first-time setup.
Lost access? Use backup wordsEmergency access with the 12 backup words, see Security.

If you created your Cloud account with GitHub, Google or Microsoft, you have no sslbrain Cloud password and need to use the button.

Signing in with the button works like this:

  1. Click Log in with sslbrain Cloud.

  2. Sign in to sslbrain Cloud with a password, GitHub, Google or Microsoft, plus two-factor authentication if it is switched on for the account.

  3. sslbrain Cloud decides the role on this particular appliance and sends the browser back with a one-time code that is valid for 5 minutes. The appliance creates or updates your login.

The role is fetched from sslbrain Cloud at every Cloud sign-in:

In sslbrain CloudRole on the appliance
Owner of the accountOwner
Member of this particular applianceThe role the member was given in Cloud
Administrator on the accountAdministrator
Anyone elseRefused with “You do not have access to this installation.”

The Billing role in sslbrain Cloud gives no access to the appliance. Membership is managed in sslbrain Cloud under Team, see sslbrain Cloud. The tab Users and login › Cloud account and users opens that page.

About signing in:

  • A session lasts 120 minutes. When it has expired, the sign-in page shows “Your session has expired. Please log in again.” and returns you to the page you were on.
  • After 30 failed attempts the form locks for a while. The message is in Danish: “For mange loginforsøg. Prøv igen om … sekunder.”
  • Every sign-in, sign-out and failed sign-in is written to the audit log.
  • If the appliance cannot reach sslbrain Cloud, it checks the password against the copy it saved at the last sign-in with a password. A Cloud user who has signed in with a password before can therefore still get in.

If signing in does not work, see When something does not work.

The appliance has four roles in a fixed order. Each role can do everything the role below it can. The role names are in English on the appliance, also when the web interface is in Danish or Swedish: Owner, Administrator, Operator and Viewer. sslbrain Cloud uses the same names for the same roles.

RoleCan
ViewerView the overview, certificates, servers, the audit log, the settings pages (without changing them) and Support.
OperatorThe same, plus: create and edit servers, credentials, profiles and certificates (including upload), create and run rules, rerun deployments, create alert channels and alert rules, edit sources, run discovery and TLS scanning, use the tools, export the audit log (if the licence allows it), and switch scheduled jobs on and off.
AdministratorThe same, plus: users, all settings, operation mode, domain lock, support partner, diagnostics, updates, restart and stop, backup, the agent catalogue and modules, accepting host keys, and all deletion.
OwnerEverything. Only an Owner can give or remove the Owner role, set a password for an Owner, delete an Owner, and change who may export private keys (Security).

Whoever claims the appliance during first-time setup becomes Owner. The role list on Users offers Administrator, Operator and Viewer.

The menu shows only what the role may use.

The last local administrator cannot be deleted or given a lower role.

Two accounts are managed by the appliance itself. They are marked System account in the list, cannot be edited or deleted, cannot sign in with the form, and do not count as logins on the licence:

  • Admin Local has the Owner role and no password. It opens only with the 12 backup words, see Security.
  • System has the Viewer role and is recorded as the actor for things the appliance does on its own.
  1. Open Users and login › Users and click Add user.

  2. Fill in username, email, password (at least 10 characters) and role. Email is required, even though the field is labelled Email (optional).

  3. Click Create user. If the appliance asks you to confirm your own sign-in, do so. The user is then created.

The user is a local user and signs in with email and password. If colleagues should sign in with their sslbrain Cloud account instead, invite them in sslbrain Cloud under Team.

A local password lets a user sign in with email and password without the appliance asking sslbrain Cloud. Give at least one user a local password, so there is a way in when sslbrain Cloud cannot be reached.

  1. Open the user menu at the top and choose Local password.

  2. Type the new password twice. It must be between 10 and 200 characters. If the account already has a local password, type the current one as well.

  3. Click Save password.

The account then becomes a local account on this appliance. The Log in with sslbrain Cloud button still works for it.

An administrator can set passwords for other users under Users (click Edit next to the user). The administrator must confirm their own sign-in first. Admin Local cannot confirm its sign-in and sets the password without it, but that password then cannot be used to confirm the user’s sign-in afterwards (Admin Local). You set your own password under Local password in the user menu. A Cloud user who is given a password this way also becomes a local account.

A login is a person who can sign in to this appliance. Admin Local and System do not count.

LicenceLogins
Free1
Basic3
Professional10
EnterpriseUnlimited

The limit is checked only when a new person gets a login: on Users, at the first sign-in with the sslbrain Cloud button, and at the first sign-in with a Cloud password. A login that already exists is never refused. When the limit is reached, the appliance shows “The licence on this appliance does not allow another login. Release one, or upgrade the licence, and try again.” Delete a login under Users, or upgrade the licence.

The count is shown on Users, for example “3 of 10 logins”, and under Appliance and licence › Overview as users used and included.

sslbrain Cloud counts in its own way: every user on the account plus pending invitations, across all the account’s appliances. The two numbers can therefore differ, see sslbrain Cloud.