What sslbrain can install on
Copy link to the page “What sslbrain can install on”sslbrain installs certificates with packages: signed scripts for one platform each, such as IIS, nginx or FortiGate. The tables below are FairSSL’s catalogue. Which packages and versions your appliance has is shown under Agents › Definitions.
How packages run
Copy link to the section “How packages run”Where a package runs depends on the platform:
| Platform | Where the package runs |
|---|---|
| Windows servers | On the server, through the service agent (Windows servers) |
| Cloud services, firewalls, load balancers, storage and vCenter | On the appliance, which calls the device’s or service’s API with the credential from Credentials (API) |
| pfSense and VMware ESXi | On the device, over SSH |
| Fortinet FortiMail | On the appliance, which drives the FortiMail command line over SSH |
When a server has an approved service agent, every action that has to happen on the server runs through the agent. The appliance queues the action as a signed task, which the agent collects at its next check-in.
Discovery on the server decides which package installs on a service: an IIS binding is installed with iis8plus, Exchange with exchange2013-2019. You choose the services in the rule (step 8).
Every package is signed by FairSSL, and the appliance and the service agents check the signature before a package runs (signing).
Agents › Definitions
Copy link to the section “Agents › Definitions”Agents › Definitions shows the packages the appliance has: what each package can do and which version is on the appliance. All users can see the page. Which versions may run is controlled under Agents › Settings.
Agents › Catalogue
Copy link to the section “Agents › Catalogue”Agents › Catalogue (the Agent catalogue page) is for administrators. For each package the page shows the versions and their signature (Verified, Invalid or Unsigned) and which version is running (Runs …).
- Preview shows the script behind the package.
- Import approves a version, and Upgrade moves to a newer one.
- The Custom agents section is for your own scripts (Your own scripts).
Agents › Settings
Copy link to the section “Agents › Settings”Agents › Settings (the Agent settings page) decides how updated versions of the packages reach the servers. The page is for administrators.
| Setting | Effect |
|---|---|
| Approve new versions automatically (recommended) | The packages always run the latest signed version, including packages you approved by hand. The signature is checked before a version is used. The switch also turns on Download new versions automatically |
| Download new versions automatically | Downloads new versions of the packages and the service agent’s installation packages from sslbrain Cloud and shows them in Agents › Catalogue, so they can be reviewed before approval |
If you turn off Approve new versions automatically (recommended), the versions running now are approved in your name, so the rules keep running. Later versions run only once an administrator has approved them in Agents › Catalogue.
The operation mode chosen during setup set the starting value: Auto turns automatic approval on, Manual turns it off.
Packages that install certificates
Copy link to the section “Packages that install certificates”Windows and Microsoft
Copy link to the section “Windows and Microsoft”11agent packages. PowerShell-based agents for Windows Server, IIS, Exchange, SQL Server, and Microsoft infrastructure.
| Agent | Platform | Package | Type | Description |
|---|---|---|---|---|
| Windows IIS 8+ | IIS 8.0+ on Windows Server 2012+ | iis8plus | FairSSL | Installs and binds certificates on IIS websites. |
| IIS Central Certificate Store | IIS Central Certificate Store | windows-ccs | FairSSL | Deploys PFX files to CCS with hostname-based file naming. |
| Microsoft Exchange 2013, 2016, 2019, SE | Exchange Server 2013, 2016, 2019, and Subscription Edition | exchange2013-2019 | FairSSL | Replaces certificates across mail and client access services. |
| Windows SQL Server | Microsoft SQL Server | windows-sql | FairSSL | Binds certificates to SQL Server instances and validates TLS. |
| Windows ADFS | Active Directory Federation Services | windows-adfs | FairSSL | Rotates ADFS service communications and SSL certificates. |
| Windows Certificate Authority | Active Directory Certificate Services | windows-ca | FairSSL | Replaces the certificate the AD CS service itself uses, restarts CertSvc and can roll back. Issuing certificates from your CA is the Windows CA source. |
| Web Application Proxy | Microsoft Web Application Proxy | windows-wap | FairSSL | Rotates WAP certificates globally or per application. |
| Windows Remote Desktop | Remote Desktop Services | windows-rdp | FairSSL | Keeps RDP endpoints on the right certificates. |
| Windows SSL/TLS Bindings | HTTP.sys and netsh bindings | windows-netsh | FairSSL | Controls SSL/TLS bindings for services using HTTP.sys without IIS. |
| Windows Certificate Store | Windows Local Machine certificate store | windows-cert-install | FairSSL | Installs PFX certificates into the Windows Certificate Store. |
| Dynamics NAV / Business Central | Microsoft Dynamics NAV and Business Central | navbc-windows | FairSSL | Manages TLS bindings for NAV/BC service instances. |
Linux and services
Copy link to the section “Linux and services”8agent packages. Packages for web servers, mail, databases, and Java application servers on Linux.
| Agent | Platform | Package | Type | Description |
|---|---|---|---|---|
| Nginx | Nginx | nginx-ssh | FairSSL | Discovers server blocks, deploys certificates, and validates reloads. |
| Apache | Apache 2.4+ | apache-ssh | FairSSL | Handles VirtualHost discovery, certificate files, and service reloads. |
| HAProxy | HAProxy | haproxy-ssh | FairSSL | Builds PEM bundles and reloads HAProxy after validation. |
| Apache Tomcat | Tomcat | tomcat-ssh | FairSSL | Updates PKCS12/JKS keystores and restarts relevant services. |
| Postfix | Postfix SMTP | postfix-ssh | FairSSL | Deploys SMTP certificates and validates Postfix configuration. |
| Dovecot | Dovecot IMAP/POP | dovecot-ssh | FairSSL | Updates Dovecot TLS configuration with rollback support. |
| PostgreSQL | PostgreSQL | postgresql-ssh | FairSSL | Installs TLS certificates with correct ownership and path handling. |
| Oracle WebLogic | Oracle WebLogic identity keystore | oracle-weblogic-ssh | FairSSL | Imports the certificate and key into the WebLogic identity keystore with keytool. |
Cloud certificate stores
Copy link to the section “Cloud certificate stores”7agent packages. CLI/API-based agents for certificates in cloud platforms.
| Agent | Platform | Package | Type | Description |
|---|---|---|---|---|
| AWS Certificate Manager | AWS ACM via AWS CLI | aws-acm-api | FairSSL | Imports and tracks certificates in AWS Certificate Manager. |
| Azure Key Vault | Azure Key Vault via Azure CLI | azure-keyvault-api | FairSSL | Manages certificates in Key Vault with Azure CLI. |
| Google Cloud Certificate Manager | Google Cloud Certificate Manager via gcloud CLI | gcloud-certmanager-api | FairSSL | Automates certificate updates in Google Cloud Certificate Manager. |
| Cloudflare | Cloudflare custom certificates via API | cloudflare-api | FairSSL | Uploads and renews custom certificates on a Cloudflare zone. |
| Akamai CPS | Akamai Certificate Provisioning System via API | akamai-cps-api | FairSSL | Uploads third-party certificates and trust chains to Akamai CPS enrollments. |
| Azure App Service | Azure App Service via Resource Manager API | azure-appservice-api | FairSSL | Uploads the certificate and binds it to App Service hostnames. |
| AWS CloudFront | AWS CloudFront via AWS CLI | aws-cloudfront-api | FairSSL | Imports the certificate into ACM in us-east-1 and updates the distribution viewer certificate. |
Appliances, networking, and virtualization
Copy link to the section “Appliances, networking, and virtualization”13agent packages. Agents for load balancers, firewalls, storage, NAS, and VMware environments.
| Agent | Platform | Package | Type | Description |
|---|---|---|---|---|
| Citrix NetScaler / ADC | NetScaler / ADC via NITRO API | netscaler-api | FairSSL | Updates cert/key pairs and vserver bindings. |
| Cisco Secure Firewall Device Manager | Cisco Secure Firewall Threat Defense via FDM API | cisco-fdm-api | FairSSL | Uploads or renews certificate objects on FDM-managed Cisco firewalls and binds them to the Web UI, RA VPN and the other targets discovery found. |
| Palo Alto Networks PAN-OS | PAN-OS firewalls via XML API | paloalto-panos-api | FairSSL | Imports the certificate and key, updates SSL/TLS service profiles, and commits the change. |
| F5 BIG-IP | F5 BIG-IP LTM via iControl REST | f5-bigip-api | FairSSL | Uploads the certificate and key, updates client-ssl profiles, and syncs in HA setups. |
| Sophos Firewall | Sophos Firewall (SFOS) via XML API | sophos-firewall-api | FairSSL | Uploads certificates to Sophos Firewall and can bind them to the admin console. |
| Fortinet FortiGate | FortiGate (FortiOS 6.4+) via REST API | fortigate-api | FairSSL | Imports the certificate and swaps the admin, SSL-VPN and IPsec certificate references. Can roll back from the captured reference backup when a deployment fails. |
| Fortinet FortiMail | FortiMail via CLI over SSH | fortimail-ssh | FairSSL | Deploys certificates through the FortiMail CLI. The FortiMail REST API cannot upload certificates, so SSH is the only programmatic path. |
| Kemp LoadMaster | Kemp LoadMaster via REST API v2 | kemp-loadmaster | FairSSL | Manages certificates on Kemp LoadMaster load balancers. |
| pfSense | pfSense over SSH | pfsense-ssh | Community | Replaces firewall and webGUI certificates on pfSense. |
| Synology DSM | Synology DSM via Web API | synology-dsm-api | FairSSL | Manages NAS certificates through the DSM API. |
| NetApp ONTAP | ONTAP via REST API | netapp-ontap-api | FairSSL | Rotates certificates on NetApp ONTAP clusters. |
| VMware vCenter | vCenter Server via REST API | vmware-vcenter-api | FairSSL | Replaces vCenter management certificates. |
| VMware ESXi | Standalone ESXi hosts over SSH | vmware-esxi-ssh | FairSSL | Updates host certificates on standalone ESXi hypervisors. |
Packages that only find certificates
Copy link to the section “Packages that only find certificates”These packages find services, bindings and certificates on a Windows server, but install no certificates. They are never chosen as a target in a rule.
- Certificates on IIS are installed with
iis8plus. - Certificates on Exchange are installed with
exchange2013-2019. - For Milestone XProtect and Veeam Backup & Replication, the catalogue has no package that installs the certificate.
| Agent | Platform | Package | Description |
|---|---|---|---|
| IIS Web Server | IIS sites and bindings | windows-iis | Discovers IIS sites, HTTPS and FTP bindings and application pools. Does not install certificates; Windows IIS 8+ (iis8plus) does. |
| Microsoft Exchange | Exchange Server certificates and services | windows-exchange | Discovers Exchange services, certificate assignments, virtual directories and transport TLS. Does not install certificates; Microsoft Exchange 2013, 2016, 2019, SE (exchange2013-2019) does. |
| Windows Server | General Windows Server inventory | windows-os | Discovers services, certificates, TLS configuration and system information on a Windows server and can import and export PFX in the LocalMachine store. Is not a deployment target in a rule. |
| Milestone XProtect | Milestone XProtect on Windows | windows-milestone | Discovers Milestone XProtect services, versions and certificate bindings. Does not install certificates. |
| Veeam Backup & Replication | Veeam Backup & Replication | windows-veeam | Discovers Veeam Backup & Replication services, versions and certificate bindings. Does not install certificates. |
Platforms not in the catalogue
Copy link to the section “Platforms not in the catalogue”Your own script for a platform the catalogue does not cover is uploaded as a custom agent. See Your own scripts and Servers sslbrain does not know.