Skip to content

Step 7 of 8

A certificate profile decides where a certificate comes from: which sources are tried, in which order, and which key types the certificate may have. The rule in step 8 chooses the profile. Most start with the Gratis Auto profile, which the appliance has created itself.

Profiles are under Setup › Certificate issuance › Profiles and sources under Sources › Sources. A certificate is always created on a profile, and the profile tries its sources from the top: if the first cannot deliver, the next is tried.

ProfileWhere it comes fromIssuer
Gratis Auto, labelled Starter profileCreated on the appliance when the licence is activatedLet’s Encrypt, then Google Trust Services, via sslbrain Cloud
Default, labelled From sslbrain CloudCreated with every sslbrain Cloud accountLet’s Encrypt, then Google Trust Services. Used by the appliance’s own certificate (step 3)
FairSSL ACME med gratis backup, labelled From sslbrain CloudCreated in sslbrain Cloud when FairSSL has linked the account to your FairSSL accountFairSSL, then Let’s Encrypt and Google Trust Services (FairSSL)
Your own profilesCreate certificate profileThe sources you choose

A profile labelled From sslbrain Cloud is managed from sslbrain Cloud. Its name, CA sources, order and key types are changed there, and the profile cannot be edited or deleted on the appliance. sslbrain Cloud moves on to the next CA in the profile by itself if a CA fails.

All users can see profiles and sources. Operators and administrators can create and edit them, and only administrators can delete a source.

  1. Open Profiles and click Create certificate profile.

  2. Give the profile a Name, for example Web and wildcard.

  3. Click Add under Certificate sources next to each source the profile should use. Move the sources up and down with the arrows: the order is the failover order.

  4. Choose Priority list failover under Choosing between sources.

  5. Choose the Default key type. It is used by certificates that do not choose a key type themselves.

  6. Click Create profile.

Gratis Auto gives free DV certificates and costs no units. The profile has one source, sslbrain Cloud Free Auto, and the default key is ECDSA P-384.

How a certificate is made:

  1. The appliance creates the key and the CSR. During issuance the private key stays on the appliance, and only the CSR is sent on. The key goes to a server only when a rule installs the certificate, and it can be exported under the private key export policy.
  2. The appliance sends a signed order to sslbrain Cloud.
  3. sslbrain Cloud orders the certificate from Let’s Encrypt and moves to Google Trust Services if Let’s Encrypt fails.
  4. The appliance completes domain validation with your CNAME redirect or DNS API credential from step 6.

The profile is created only once: if you rename or delete it, sslbrain does not create it again.

FairSSL certificates are ordered through sslbrain Cloud. The appliance’s rule orders through the profile, so nothing has to be ordered by hand in sslbrain Cloud.

  1. Contact FairSSL and ask for your sslbrain Cloud account to be linked to your FairSSL account.

  2. sslbrain Cloud creates the profile FairSSL ACME med gratis backup. It tries FairSSL first and falls back to Let’s Encrypt and Google Trust Services. The profile arrives on the appliance by itself, labelled From sslbrain Cloud.

  3. Choose the profile in the rule in step 8.

For DigiCert certificates via FairSSL, the domain needs the record _dnsauth.<domain>. It is checked on every order; see CNAME delegation.

A source of the type sslbrain Cloud certificate order has the list Products, which shows the products sslbrain Cloud offers the account. Products that cost units are paid for with units you buy in sslbrain Cloud under Licenser og units (units).

The Sources › Sources page (heading Certificate sources) shows the appliance’s own sources and the list Sources in sslbrain Cloud. New sources are created with Add source:

SourceFor
sslbrain Cloud certificate orderA signed certificate order through sslbrain Cloud. The private key stays on the appliance
Windows CACertificates from your own AD CS (Windows CA)
Manual certificate uploadCertificates you upload yourselves (upload)

When a certificate is to be issued or renewed, the profile skips a source that is in error, cannot issue the key type the certificate needs, or has no enabled product that covers the names. A temporary error is retried once on the same source before the next source takes over. Every renewal starts again from the top of the list.

An owner or administrator can block a source from sslbrain Cloud on this appliance with Block on this appliance. No certificates are then issued through it here until the block is lifted.

The Windows CA source gets certificates from your own Active Directory Certificate Services. The service agent on a Windows server sends the request to the CA, and the private key stays on the appliance. The source needs the Enterprise licence, the Windows CA add-on, which FairSSL enables on the licence, and the Windows CA module.

The setup is in Internal certificates from Windows CA.

A certificate from a CA that sslbrain does not order from can be uploaded under Certificates with Upload certificate.

  • Formats: PEM, CRT, CER, DER, PFX, P12 and JKS. P7B is not accepted.
  • Fields that can be left out: display name, private key file, chain (PEM) and the container password. At most 5 MB per file.
  • Without a private key, the certificate is used only for monitoring and expiry dates. Deployment needs the matching key.
  • sslbrain does not renew an uploaded certificate with a CA. A later edition is uploaded with Upload new version on the certificate.

An uploaded certificate that does not belong to an existing certificate is put on the profile Manual upload. Uploading from discovery is in step 4.

  • Profiles shows Gratis Auto labelled Starter profile, and the profiles you have from sslbrain Cloud labelled From sslbrain Cloud.
  • Each profile shows its sources in the order they are tried.
  • A profile where no source can issue shows No source can issue right now and a link to the source that is in error.
  • Gratis Auto is missing: the profile is created when the licence is activated, and only when the appliance is connected to sslbrain Cloud. Check that the appliance is connected to sslbrain Cloud.
  • The profile shows No source can issue right now: open the source from the link and correct the error. See also Renewal fails.
  • Issuance stops at domain validation: see Validation fails.