The certificate has to land on the server
Issuing a certificate is the easy part. The hard part is installing it correctly on an Exchange server, binding it in IIS, reloading HAProxy, or updating a NetScaler without downtime. sslbrain agents own exactly that step: each agent knows its platform and performs installation, binding, and reload with validation and rollback.
Push or pull
Push agents run from the appliance over SSH for Linux, WinRM for Windows, or REST APIs for appliances and cloud services. The pull model uses the Windows Service Agent, an MSI package you can roll out via GPO, SCCM, or Intune. It fetches tasks from sslbrain over outbound HTTPS, so there are no firewall openings and no WinRM to enable.
Signed code, your policy
Every agent package is signed with ECDSA P-384, and every server carries a ScriptPolicy deciding what it accepts: FairSSL-signed agents only, verified community agents, or your own custom agents. Browse the full catalog on the features page and the principles under policy management.