Skip to content

sslbrain installs certificates with packages: signed scripts for one platform each, such as IIS, nginx or FortiGate. The tables below are FairSSL’s catalogue. Which packages and versions your appliance has is shown under Agents › Definitions.

Where a package runs depends on the platform:

PlatformWhere the package runs
Windows serversOn the server, through the service agent (Windows servers)
Cloud services, firewalls, load balancers, storage and vCenterOn the appliance, which calls the device’s or service’s API with the credential from Credentials (API)
pfSense and VMware ESXiOn the device, over SSH
Fortinet FortiMailOn the appliance, which drives the FortiMail command line over SSH

When a server has an approved service agent, every action that has to happen on the server runs through the agent. The appliance queues the action as a signed task, which the agent collects at its next check-in.

Discovery on the server decides which package installs on a service: an IIS binding is installed with iis8plus, Exchange with exchange2013-2019. You choose the services in the rule (step 8).

Every package is signed by FairSSL, and the appliance and the service agents check the signature before a package runs (signing).

Agents › Definitions shows the packages the appliance has: what each package can do and which version is on the appliance. All users can see the page. Which versions may run is controlled under Agents › Settings.

Agents › Catalogue (the Agent catalogue page) is for administrators. For each package the page shows the versions and their signature (Verified, Invalid or Unsigned) and which version is running (Runs …).

  • Preview shows the script behind the package.
  • Import approves a version, and Upgrade moves to a newer one.
  • The Custom agents section is for your own scripts (Your own scripts).

Agents › Settings (the Agent settings page) decides how updated versions of the packages reach the servers. The page is for administrators.

SettingEffect
Approve new versions automatically (recommended)The packages always run the latest signed version, including packages you approved by hand. The signature is checked before a version is used. The switch also turns on Download new versions automatically
Download new versions automaticallyDownloads new versions of the packages and the service agent’s installation packages from sslbrain Cloud and shows them in Agents › Catalogue, so they can be reviewed before approval

If you turn off Approve new versions automatically (recommended), the versions running now are approved in your name, so the rules keep running. Later versions run only once an administrator has approved them in Agents › Catalogue.

The operation mode chosen during setup set the starting value: Auto turns automatic approval on, Manual turns it off.

11agent packages. PowerShell-based agents for Windows Server, IIS, Exchange, SQL Server, and Microsoft infrastructure.

AgentPlatformPackageTypeDescription
Windows IIS 8+IIS 8.0+ on Windows Server 2012+iis8plusFairSSLInstalls and binds certificates on IIS websites.
IIS Central Certificate StoreIIS Central Certificate Storewindows-ccsFairSSLDeploys PFX files to CCS with hostname-based file naming.
Microsoft Exchange 2013, 2016, 2019, SEExchange Server 2013, 2016, 2019, and Subscription Editionexchange2013-2019FairSSLReplaces certificates across mail and client access services.
Windows SQL ServerMicrosoft SQL Serverwindows-sqlFairSSLBinds certificates to SQL Server instances and validates TLS.
Windows ADFSActive Directory Federation Serviceswindows-adfsFairSSLRotates ADFS service communications and SSL certificates.
Windows Certificate AuthorityActive Directory Certificate Serviceswindows-caFairSSLReplaces the certificate the AD CS service itself uses, restarts CertSvc and can roll back. Issuing certificates from your CA is the Windows CA source.
Web Application ProxyMicrosoft Web Application Proxywindows-wapFairSSLRotates WAP certificates globally or per application.
Windows Remote DesktopRemote Desktop Serviceswindows-rdpFairSSLKeeps RDP endpoints on the right certificates.
Windows SSL/TLS BindingsHTTP.sys and netsh bindingswindows-netshFairSSLControls SSL/TLS bindings for services using HTTP.sys without IIS.
Windows Certificate StoreWindows Local Machine certificate storewindows-cert-installFairSSLInstalls PFX certificates into the Windows Certificate Store.

8agent packages. Packages for web servers, mail, databases, and Java application servers on Linux.

AgentPlatformPackageTypeDescription
NginxNginxnginx-sshFairSSLDiscovers server blocks, deploys certificates, and validates reloads.
ApacheApache 2.4+apache-sshFairSSLHandles VirtualHost discovery, certificate files, and service reloads.
HAProxyHAProxyhaproxy-sshFairSSLBuilds PEM bundles and reloads HAProxy after validation.
Apache TomcatTomcattomcat-sshFairSSLUpdates PKCS12/JKS keystores and restarts relevant services.
PostfixPostfix SMTPpostfix-sshFairSSLDeploys SMTP certificates and validates Postfix configuration.
DovecotDovecot IMAP/POPdovecot-sshFairSSLUpdates Dovecot TLS configuration with rollback support.
PostgreSQLPostgreSQLpostgresql-sshFairSSLInstalls TLS certificates with correct ownership and path handling.
Oracle WebLogicOracle WebLogic identity keystoreoracle-weblogic-sshFairSSLImports the certificate and key into the WebLogic identity keystore with keytool.

7agent packages. CLI/API-based agents for certificates in cloud platforms.

AgentPlatformPackageTypeDescription
AWS Certificate ManagerAWS ACM via AWS CLIaws-acm-apiFairSSLImports and tracks certificates in AWS Certificate Manager.
Azure Key VaultAzure Key Vault via Azure CLIazure-keyvault-apiFairSSLManages certificates in Key Vault with Azure CLI.
Google Cloud Certificate ManagerGoogle Cloud Certificate Manager via gcloud CLIgcloud-certmanager-apiFairSSLAutomates certificate updates in Google Cloud Certificate Manager.
CloudflareCloudflare custom certificates via APIcloudflare-apiFairSSLUploads and renews custom certificates on a Cloudflare zone.
Akamai CPSAkamai Certificate Provisioning System via APIakamai-cps-apiFairSSLUploads third-party certificates and trust chains to Akamai CPS enrollments.
Azure App ServiceAzure App Service via Resource Manager APIazure-appservice-apiFairSSLUploads the certificate and binds it to App Service hostnames.
AWS CloudFrontAWS CloudFront via AWS CLIaws-cloudfront-apiFairSSLImports the certificate into ACM in us-east-1 and updates the distribution viewer certificate.

13agent packages. Agents for load balancers, firewalls, storage, NAS, and VMware environments.

AgentPlatformPackageTypeDescription
Citrix NetScaler / ADCNetScaler / ADC via NITRO APInetscaler-apiFairSSLUpdates cert/key pairs and vserver bindings.
Cisco Secure Firewall Device ManagerCisco Secure Firewall Threat Defense via FDM APIcisco-fdm-apiFairSSLUploads or renews certificate objects on FDM-managed Cisco firewalls and binds them to the Web UI, RA VPN and the other targets discovery found.
Palo Alto Networks PAN-OSPAN-OS firewalls via XML APIpaloalto-panos-apiFairSSLImports the certificate and key, updates SSL/TLS service profiles, and commits the change.
F5 BIG-IPF5 BIG-IP LTM via iControl RESTf5-bigip-apiFairSSLUploads the certificate and key, updates client-ssl profiles, and syncs in HA setups.
Sophos FirewallSophos Firewall (SFOS) via XML APIsophos-firewall-apiFairSSLUploads certificates to Sophos Firewall and can bind them to the admin console.
Fortinet FortiGateFortiGate (FortiOS 6.4+) via REST APIfortigate-apiFairSSLImports the certificate and swaps the admin, SSL-VPN and IPsec certificate references. Can roll back from the captured reference backup when a deployment fails.
Fortinet FortiMailFortiMail via CLI over SSHfortimail-sshFairSSLDeploys certificates through the FortiMail CLI. The FortiMail REST API cannot upload certificates, so SSH is the only programmatic path.
Kemp LoadMasterKemp LoadMaster via REST API v2kemp-loadmasterFairSSLManages certificates on Kemp LoadMaster load balancers.
pfSensepfSense over SSHpfsense-sshCommunityReplaces firewall and webGUI certificates on pfSense.
Synology DSMSynology DSM via Web APIsynology-dsm-apiFairSSLManages NAS certificates through the DSM API.
NetApp ONTAPONTAP via REST APInetapp-ontap-apiFairSSLRotates certificates on NetApp ONTAP clusters.
VMware vCentervCenter Server via REST APIvmware-vcenter-apiFairSSLReplaces vCenter management certificates.
VMware ESXiStandalone ESXi hosts over SSHvmware-esxi-sshFairSSLUpdates host certificates on standalone ESXi hypervisors.

These packages find services, bindings and certificates on a Windows server, but install no certificates. They are never chosen as a target in a rule.

  • Certificates on IIS are installed with iis8plus.
  • Certificates on Exchange are installed with exchange2013-2019.
  • For Milestone XProtect and Veeam Backup & Replication, the catalogue has no package that installs the certificate.
AgentPlatformPackageDescription
IIS Web ServerIIS sites and bindingswindows-iisDiscovers IIS sites, HTTPS and FTP bindings and application pools. Does not install certificates; Windows IIS 8+ (iis8plus) does.
Microsoft ExchangeExchange Server certificates and serviceswindows-exchangeDiscovers Exchange services, certificate assignments, virtual directories and transport TLS. Does not install certificates; Microsoft Exchange 2013, 2016, 2019, SE (exchange2013-2019) does.
Windows ServerGeneral Windows Server inventorywindows-osDiscovers services, certificates, TLS configuration and system information on a Windows server and can import and export PFX in the LocalMachine store. Is not a deployment target in a rule.
Milestone XProtectMilestone XProtect on Windowswindows-milestoneDiscovers Milestone XProtect services, versions and certificate bindings. Does not install certificates.
Veeam Backup & ReplicationVeeam Backup & Replicationwindows-veeamDiscovers Veeam Backup & Replication services, versions and certificate bindings. Does not install certificates.

Your own script for a platform the catalogue does not cover is uploaded as a custom agent. See Your own scripts and Servers sslbrain does not know.