When the appliance is down
Copy link to the page “When the appliance is down”sslbrain is a single appliance. While it is down, the certificates on your servers keep working, but nothing is renewed, deployed or alerted until it is back. Whether a certificate expires during an outage depends on how much time it has left (What keeps working).
When you need this
Copy link to the section “When you need this”When you need to know what an outage means for operations before it happens, for example for a contingency plan, or when the appliance is down now and has to come back.
What keeps working
Copy link to the section “What keeps working”| Part | While the appliance is down |
|---|---|
| Certificates on your servers | Work until they expire. They are installed on the servers and do not depend on the appliance. |
| Renewal | Waits. Once the appliance is up, it looks for certificates due for renewal within 3 hours. |
| Service agents | Keep running on the servers and retry at growing intervals. They check in when the appliance answers. |
| Alerts | Not sent. The appliance is what sends them. |
A certificate of 90 days or less is renewed when two thirds of its validity has passed. A 90-day certificate is therefore renewed about 30 days before expiry, and a longer certificate 30 days before. A certificate that sslbrain has renewed and installed on time therefore normally has weeks left. Two kinds of certificate can be close to expiry when the appliance goes down:
- an uploaded certificate, which sslbrain does not renew;
- a certificate whose renewal or deployment has already failed.
When you plan how to bring the appliance back, check when the first certificate expires. The Expiring certificates card on Overview shows those expiring within 30 days, and Certificates lists the one expiring first at the top.
If a certificate became due for renewal while the appliance was down, it is renewed at the first check once the appliance is back. See First certificate on a server.
An agent installed with an install code waits at most an hour between attempts by default (Largest backoff (seconds) under Agents › Connection, see How the agent reaches the appliance). A Windows agent installed without an install code can wait up to a day between attempts, so it will not necessarily check in the moment the appliance is back.
Alerts about the appliance itself must come from your own monitoring system. Monitor the appliance’s HTTPS address from there.
Bring the appliance back
Copy link to the section “Bring the appliance back”Start with the smallest intervention and move on if it does not help.
-
Restart the appliance. If the web interface responds, click Restart under Appliance and licence › System. Otherwise choose
5 Restart the appliancein the console menu on the virtual machine. If that does not help, choose8 Reboot this machine. See Console menu. -
Open the vault. At start-up the appliance opens its vault with a key from sslbrain Cloud. If it cannot reach sslbrain Cloud, the vault opens by itself once the connection is back. If you need to get in before then, log in with the 12 backup words, see When something does not work.
-
If the appliance software is broken, choose
9 Danger zoneand6 Reinstall the appliance software (data kept)in the console menu. It downloads the running version again and keeps certificates, settings, accounts and the database. See Keep sslbrain up to date. -
If data is damaged, restore a backup on the same appliance and then open it with the 12 backup words. See Save a backup and restore from it.
-
If the machine is lost, move the licence to a new appliance and set it up. Data does not move with the licence. See Move or restore the appliance.
If an update fails, the appliance keeps running the version it had, so a failed update does not take the appliance down. See When something does not work.
If the appliance shows Installation locked when it comes up, see Installation locked.