ActivCERT

CERTCOM Commands and Parameters

Use HELP in CERTCOM for command syntax matching your installed version.

Command: Repeat

! Command

Causes a previous command to be executed.

Command attributes:
  Session: Not required
  Destructive: No

  ! [ [ - ] <number> | <character-string> ]

Command target:

[ - ] <number> | <character-string>

  The command number or the first few characters of the command to be
  re-executed.

Command: ALLOW

ALLOW Command

Specifies the maximum number of warnings or errors that are allowed to occur
before execution of an OBEY file or IN file is terminated.

Command attributes:
  Session: Not required
  Destructive: No

  ALLOW [ [ <count> | ALL | NO ] [ ERRORS | WARNINGS ] ]

Command target:

[ <count> | ALL | NO ] [ ERRORS | WARNINGS ]

  ALL indicates that there is no limit on the number of errors or warnings. NO
  indicates that no errors or warnings are allowed. <count> is an integer
  specifying the number or errors or warnings. If the ALLOW command is used
  with no parameters, the default setting is NO ERRORS and ALL WARNINGS. If
  ERRORS or WARNINGS is specified but ALL, NO, and <count> are omitted, ALL is
  assumed. IF ALL, NO, or <count> is specified, but ERRORS and WARNINGS are
  omitted, ERRORS is assumed.

Command: CLOSE

CLOSE Command

Closes the active CERTCOM session.

Command attributes:
  Session: Required
  Destructive: No

  CLOSE

Command: ENV

ENV Command

Displays information about the program environment.

Command attributes:
  Session: Not required
  Destructive: No

  ENV

Command: EXIT

EXIT Command

Stops the program.

Command attributes:
  Session: Not required
  Destructive: No

  EXIT

Command: FC

FC Command

Causes a previous command to be executed.

Command attributes:
  Session: Not required
  Destructive: No

  FC [ [ - ] <number> | <string> ]

Command target:

[ - ] <number> | <string>

  The command number or the first few characters of the command to fix.

Command: HELP

HELP Command

Displays the syntax for commands.

Command attributes:
  Session: Not required
  Destructive: No

  HELP [ help-spec ]

Command target:

help-spec

  The command and/or object for which help should be displayed.

Command: HISTORY

HISTORY Command

Shows the most recent commands.

Command attributes:
  Session: Not required
  Destructive: No

  HISTORY [ <number> ]

Command target:

<number>

  The number of commands to be displayed. If omitted, the 10 most recent
  commands are displayed.

Command: OBEY

OBEY Command

Causes commands to be read from a command file.

Command attributes:
  Session: Not required
  Destructive: No

  OBEY obey-file

Command target:

obey-file

  The command file from which commands are to be read.

Command: OPEN

OPEN Command

Opens a CERTCOM session with an ActivCERT monitor.

Command attributes:
  Session: Not required
  Destructive: No

  OPEN <process-name>

Command target:

<process-name>

  The Guardian process name of the ActivCERT monitor.

Command: PAGESIZE

PAGESIZE Command

Sets the size of a display page on the terminal screen.

Command attributes:
  Session: Not required
  Destructive: No

  PAGESIZE [ <integer> ]

Command target:

<integer>

  If <integer> in the range 2 - 255, <integer> lines will be displayed before
  providing a page break. If omitted or -1, output will be displayed without
  page breaks. If omitted, the default value is "-1".

Command: STATUS

STATUS Command

Displays ActivCERT product health.

Reports monitor health, datastore and service state, scheduler state, open
work, expiration risk, recent failures, and recommended operator actions.

Command attributes:
  Session: Required
  Destructive: No

  STATUS
         [ , DETAIL ]

Output options:

DETAIL

  Displays the last scheduler scan time.

Command: VOLUME

VOLUME Command

Specifies the default subvolume for the expansion of all file names.

Command attributes:
  Session: Not required
  Destructive: No

  VOLUME [ <subvolume-name> ]

Command target:

<subvolume-name>

  The name of the subvolume that is to become the default.  If omitted, the
  program default subvolume is used.

Command: ADD CERTIFICATE

ADD CERTIFICATE Command

Creates a managed certificate.

Configuration object names accept any ASCII letter case when referenced;
stored spelling is preserved and case-only duplicates are rejected. Missing
references identify the failed object type and name. Correct the first
reported reference and retry; use the suggested INFO collection to check
configured names.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD CERTIFICATE <certificate-name>, ISSUER <issuer-name>, RENEWAL-POLICY
  <policy-name>, KEY-POLICY <key-policy-name> [ , PRIVATE-KEY
  <credential-name> ], SUBJECT <subject> [ , SAN <san-list> ]

Command target:

<certificate-name>

  The managed certificate name.

Properties:

ISSUER <issuer-name>

  The certificate issuer.

RENEWAL-POLICY <policy-name>

  The renewal policy.

KEY-POLICY <key-policy-name>

  The certificate key policy.

PRIVATE-KEY <credential-name>

  The private key credential required by an imported-key policy.

SUBJECT <subject>

  DNS hostname (stored as CN=<hostname>) or comma-separated attribute=value
  DN. Attribute names accept any case; values are preserved. Omitted SAN
  defaults to a single DNS common name.

SAN <san-list>

  The certificate subject alternative names. DNS, IP, URI and email prefixes
  accept any case; values are preserved.

Command: ADOPT CERTIFICATE

ADOPT CERTIFICATE Command

Brings an existing certificate installation under management.

Command attributes:
  Session: Required
  Destructive: Yes

  ADOPT CERTIFICATE <certificate-name>, SOURCE FILE, TARGET <target-name>,
  ISSUER <issuer-name>, RENEWAL-POLICY <policy-name>, KEY-POLICY
  <key-policy-name>, FORMAT PEM-SEPARATE, FILE-TYPE EDIT | STREAM, CERT-FILE
  <guardian-file>, KEY-FILE <guardian-file> [ , CHAIN-FILE <guardian-file> ] [
  , FULLCHAIN-FILE <guardian-file> ] [ , WAIT ]
  ADOPT CERTIFICATE <certificate-name>, SOURCE FILE, TARGET <target-name>,
  ISSUER <issuer-name>, RENEWAL-POLICY <policy-name>, KEY-POLICY
  <key-policy-name>, FORMAT PEM-FULLCHAIN, FILE-TYPE EDIT | STREAM,
  FULLCHAIN-FILE <guardian-file>, KEY-FILE <guardian-file> [ , WAIT ]
  ADOPT CERTIFICATE <certificate-name>, SOURCE FILE, TARGET <target-name>,
  ISSUER <issuer-name>, RENEWAL-POLICY <policy-name>, KEY-POLICY
  <key-policy-name>, FORMAT PKCS12, FILE-TYPE BINARY, PKCS12-FILE
  <guardian-file>, PASSPHRASE <credential-name> | NO-PASSPHRASE [ , WAIT ]
  ADOPT CERTIFICATE <certificate-name>, SOURCE LIGHTWAVE, TARGET
  <target-name>, ISSUER <issuer-name>, RENEWAL-POLICY <policy-name>,
  KEY-POLICY <key-policy-name>, PROGRAM-FILE <guardian-file>, CERT-SPEC
  <certificate-spec>, PASSPHRASE <credential-name> [ , COMMON-NAME
  <common-name> ] [ , IMPORT-CHAIN ON | OFF ] [ , EXPORT-CHAIN ON | OFF ] [ ,
  WAIT ]

Command target:

<certificate-name>

  The managed certificate name.

Action options:

SOURCE FILE | LIGHTWAVE

  The certificate onboarding source.

TARGET <target-name>

  The source target name to create.

ISSUER <issuer-name>

  The certificate issuer.

RENEWAL-POLICY <policy-name>

  The renewal policy.

KEY-POLICY <key-policy-name>

  The certificate key policy.

PROGRAM-FILE <guardian-file>

  The fully qualified LWSCOM or LWCCOM program file.

CERT-SPEC <certificate-spec>

  The LWxCOM certificate specification.

COMMON-NAME <common-name>

  Display metadata for the LightWave target.

IMPORT-CHAIN ON | OFF

  Controls future chain import through LWxCOM.

EXPORT-CHAIN ON | OFF

  Controls source chain export through LWxCOM.

FORMAT PEM-SEPARATE | PEM-FULLCHAIN | PKCS12

  The Guardian file source and target format.

FILE-TYPE EDIT | STREAM | BINARY

  The Guardian file type.

CERT-FILE <guardian-file>

  The separate PEM certificate file.

KEY-FILE <guardian-file>

  The PEM private key file.

CHAIN-FILE <guardian-file>

  The separate PEM chain file.

FULLCHAIN-FILE <guardian-file>

  Full-chain source for PEM-FULLCHAIN; optional deployment output for
  PEM-SEPARATE (uses REPLACE-OR-CREATE).

PKCS12-FILE <guardian-file>

  The PKCS12 certificate archive.

PASSPHRASE <credential-name>

  The PKCS12 passphrase credential.

NO-PASSPHRASE

  The PKCS12 archive has an empty passphrase.

WAIT

  Waits for submitted work to finish.

Command: ALTER CERTIFICATE

ALTER CERTIFICATE Command

Changes a managed certificate.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER CERTIFICATE <certificate-name> [ , NAME <new-name> ] [ , ISSUER
  <issuer-name> ] [ , RENEWAL-POLICY <policy-name> ] [ , KEY-POLICY
  <key-policy-name> ] [ , PRIVATE-KEY <credential-name> ] [ , SUBJECT
  <subject> ] [ , SAN <san-list> ] [ , ENABLED ON | OFF ]
  ALTER CERTIFICATE <certificate-name>, VERSION <number>, QUARANTINE ON,
  REASON <reason>
  ALTER CERTIFICATE <certificate-name>, VERSION <number>, QUARANTINE OFF

Command target:

<certificate-name>

  The managed certificate name.

Properties:

VERSION <number>

  A positive version number within this certificate.

QUARANTINE ON | OFF

  Controls deployment quarantine for the selected version.

REASON <text>

  Records why the version is quarantined.

NAME <new-name>

  The new managed certificate name.

ISSUER <issuer-name>

  The certificate issuer.

RENEWAL-POLICY <policy-name>

  The renewal policy.

KEY-POLICY <key-policy-name>

  The certificate key policy.

PRIVATE-KEY <credential-name>

  The private key credential required by an imported-key policy.

SUBJECT <subject>

  DNS hostname (stored as CN=<hostname>) or comma-separated attribute=value
  DN. Attribute names accept any case; values are preserved. Omitted SAN
  defaults to a single DNS common name.

SAN <san-list>

  The certificate subject alternative names. DNS, IP, URI and email prefixes
  accept any case; values are preserved.

ENABLED ON | OFF

  Controls whether the managed certificate may be processed.

Command: DELETE CERTIFICATE

DELETE CERTIFICATE Command

Deletes a disabled, unreferenced managed certificate.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE CERTIFICATE <certificate-name>

Command target:

<certificate-name>

  The managed certificate name.

Command: DEPLOY CERTIFICATE

DEPLOY CERTIFICATE Command

Submits deployment work for a managed certificate.

Command attributes:
  Session: Required
  Destructive: Yes

  DEPLOY CERTIFICATE <certificate-name>
         [ , TARGET <target-name> ]
         [ , OVERRIDE-WINDOW ]
         [ , WAIT ]

Command target:

<certificate-name>

  The managed certificate name.

Action options:

TARGET <target-name>

  Selects one deployment target.

OVERRIDE-WINDOW

  Starts the deployment outside its configured maintenance window.

WAIT

  Waits for submitted deployment work.

Command: INFO CERTIFICATE

INFO CERTIFICATE Command

Displays managed certificates and their current version state.
Timestamps use
whole-second UTC display without rounding.

Command attributes:
  Session: Required
  Destructive: No

  INFO CERTIFICATE <certificate-name> [ , DETAIL ]
  INFO CERTIFICATE <certificate-name>, LINKS
  INFO CERTIFICATE <certificate-name>, VERSIONS [ , DETAIL ]
  INFO CERTIFICATE <certificate-name>, VERSION <number> [ , DETAIL ]
  INFO CERTIFICATE <certificate-name>, HISTORY [ , RECENT <count> ]
  INFO CERTIFICATE * [ , ENABLED | DISABLED ] [ , EXPIRING [ , DAYS <count> ]
  ]

Command target:

<certificate-name> | *

  The certificate name, or * for all certificates.

Selection filters:

VERSION <number>

  A positive version number within this certificate.

VERSIONS

  Lists stored versions of this certificate.

ENABLED

  Selects enabled certificates.

DISABLED

  Selects disabled certificates.

EXPIRING

  Selects expiring certificates.

DAYS <count>

  Overrides the configured certificate expiration window.

Output options:

DETAIL

  Displays additional stored version information when VERSION or VERSIONS is
  selected.

HISTORY

  Displays the managed certificate lifecycle.

LINKS

  Displays the certificate and its current related objects.

Command: ISSUE CERTIFICATE

ISSUE CERTIFICATE Command

Submits initial issuance and eligible target deployment work.
DEPLOY-AFTER-RENEW must be ON for the renewal policy and target.
WAIT includes
selected deployment work; deployment windows apply.

Command attributes:
  Session: Required
  Destructive: Yes

  ISSUE CERTIFICATE <certificate-name>
        [ , WAIT ]

Command target:

<certificate-name>

  The managed certificate name.

Action options:

WAIT

  Waits for submitted work to finish.

Command: RENEW CERTIFICATE

RENEW CERTIFICATE Command

Submits certificate renewal work.

Command attributes:
  Session: Required
  Destructive: Yes

  RENEW CERTIFICATE <certificate-name>
        [ , FORCE ]
        [ , WAIT ]

Command target:

<certificate-name>

  The managed certificate name.

Action options:

FORCE

  Bypasses renewal due-state checks when allowed.

WAIT

  Waits for submitted renewal work.

Command: STATUS CERTIFICATE

STATUS CERTIFICATE Command

Displays dynamic certificate and renewal state.

Command attributes:
  Session: Required
  Destructive: No

  STATUS CERTIFICATE <certificate-name>
         [ , DETAIL ]

Command target:

<certificate-name>

  The managed certificate name.

Output options:

DETAIL

  Displays additional certificate information.

Command: ALTER CONFIGURATION

ALTER CONFIGURATION Command

Changes ActivCERT configuration properties.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER CONFIGURATION
        [ , CERTIFICATE-VERSION-RETENTION <seconds> ]
        [ , DIAGNOSTIC-RETENTION <seconds> ]
        [ , TASK-RETENTION <seconds> ]
        [ , EVENT-RETENTION <seconds> ]
        [ , ACME-ORDER-RETENTION <seconds> ]
        [ , RUNTIME-STATUS-RETENTION <seconds> ]
        [ , SNAPSHOT-RETENTION <seconds> ]
        [ , SHUTDOWN-DRAIN-TIMEOUT <seconds> ]
        [ , MAXIMUM-ACME-WORKERS <count> ]
        [ , MAXIMUM-LIGHTWAVE-WORKERS <count> ]
        [ , MAXIMUM-FILE-WORKERS <count> ]
        [ , ACME-USER-AGENT <string>|* ]

Properties:

CERTIFICATE-VERSION-RETENTION <seconds>

  The certificate-version retention period.

DIAGNOSTIC-RETENTION <seconds>

  The diagnostic-artifact retention period.

TASK-RETENTION <seconds>

  The completed-task retention period.

EVENT-RETENTION <seconds>

  The event retention period.

ACME-ORDER-RETENTION <seconds>

  The ACME order retention period.

RUNTIME-STATUS-RETENTION <seconds>

  The stopped runtime-status retention period.

SNAPSHOT-RETENTION <seconds>

  The completed work snapshot retention period.

SHUTDOWN-DRAIN-TIMEOUT <seconds>

  The maximum graceful shutdown drain period.

MAXIMUM-ACME-WORKERS <count>

  The maximum number of concurrent ACME workers.

MAXIMUM-LIGHTWAVE-WORKERS <count>

  The maximum number of concurrent LightWave workers.

MAXIMUM-FILE-WORKERS <count>

  The maximum number of concurrent Guardian file workers.

ACME-USER-AGENT <string>|*

  The complete ACME HTTP User-Agent (1-128 printable ASCII characters). Use *
  to reset to ActivCERT.

Command: INFO CONFIGURATION

INFO CONFIGURATION Command

Displays the active ActivCERT configuration.

Command attributes:
  Session: Required
  Destructive: No

  INFO CONFIGURATION
       [ , DETAIL ]

Output options:

DETAIL

  Displays additional configuration information.

Command: ADD CREDENTIAL

ADD CREDENTIAL Command

Creates a protected credential.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD CREDENTIAL <credential-name>, TYPE <credential-type>, ( PROMPT |
  FROM-FILE <guardian-file> ) [ , OWNER <entity-type> <entity-name> ]

Command target:

<credential-name>

  The credential name.

Properties:

TYPE ACME-ACCOUNT-KEY | EAB-SECRET | PKCS12-PASSPHRASE | PRIVATE-KEY | GENERAL-SECRET

  The protected value type; EAB-SECRET accepts CA-provided base64url HMAC
  text.

PROMPT

  Prompts for the protected value.

FROM-FILE <guardian-file>

  Reads the protected value from a file.

OWNER <entity-type> <entity-name>

  Associates the credential with an owner.

Command: ALTER CREDENTIAL

ALTER CREDENTIAL Command

Changes credential properties or creates a new protected secret version.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER CREDENTIAL <credential-name> [ , NAME <new-name> ] [ , PROMPT |
  FROM-FILE <guardian-file> ] [ , ENABLED ON | OFF ]

Command target:

<credential-name>

  The credential name.

Properties:

NAME <new-name>

  The new credential name.

PROMPT

  Prompts for the protected value.

FROM-FILE <guardian-file>

  Reads the protected value from a file.

ENABLED ON | OFF

  Controls whether the credential may be used.

Command: DELETE CREDENTIAL

DELETE CREDENTIAL Command

Deletes an unreferenced credential.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE CREDENTIAL <credential-name>

Command target:

<credential-name>

  The credential name.

Command: INFO CREDENTIAL

INFO CREDENTIAL Command

Displays one or more credentials without protected values.

Command attributes:
  Session: Required
  Destructive: No

  INFO CREDENTIAL <credential-name> [ , DETAIL ]
  INFO CREDENTIAL * [ , TYPE <credential-type> ] [ , ENABLED | DISABLED ]

Command target:

<credential-name> | *

  The credential name, or * for all credentials.

Selection filters:

TYPE ACME-ACCOUNT-KEY | EAB-SECRET | PKCS12-PASSPHRASE | PRIVATE-KEY | GENERAL-SECRET

  The protected value type; EAB-SECRET accepts CA-provided base64url HMAC
  text.

ENABLED

  Selects enabled credentials.

DISABLED

  Selects disabled credentials.

Output options:

DETAIL

  Displays credential metadata and diagnostics.

Command: CREATE DATASTORE

CREATE DATASTORE Command

Creates an ActivCERT datastore at an explicit Guardian location.

Command attributes:
  Session: Not required
  Destructive: Yes

  CREATE DATASTORE *|<subvol>|<volume>.<subvol>

Command target:

*|<subvol>|<volume>.<subvol>

  The Guardian subvolume where the datastore will be created; * selects the
  current subvolume.

Command: DELETE DATASTORE

DELETE DATASTORE Command

Deletes an ActivCERT datastore after confirming its explicit location.

Command attributes:
  Session: Not required
  Destructive: Yes

  DELETE DATASTORE *|<subvol>|<volume>.<subvol>, CONFIRM
  *|<subvol>|<volume>.<subvol>

Command target:

*|<subvol>|<volume>.<subvol>

  The Guardian subvolume containing the datastore to delete; * selects the
  current subvolume.

Action options:

CONFIRM *|<subvol>|<volume>.<subvol>

  Repeats the datastore location to confirm deletion; * selects the current
  subvolume.

Command: INFO DATASTORE

INFO DATASTORE Command

Displays information about the active or explicitly located ActivCERT
datastore.

Command attributes:
  Session: Not required
  Destructive: No

  INFO DATASTORE [*|<subvol>|<volume>.<subvol>] [, DETAIL]

Command target:

*|<subvol>|<volume>.<subvol>

  The datastore location; * selects the current subvolume.

Output options:

DETAIL

  Displays additional datastore information.

Command: VALIDATE DATASTORE

VALIDATE DATASTORE Command

Validates an ActivCERT datastore at an explicit Guardian location.

Command attributes:
  Session: Not required
  Destructive: No

  VALIDATE DATASTORE *|<subvol>|<volume>.<subvol>
           [ , DETAIL ]

Command target:

*|<subvol>|<volume>.<subvol>

  The datastore location; * selects the current subvolume.

Output options:

DETAIL

  Displays additional datastore information.

Command: INFO DCV

INFO DCV Command

Displays one or more DCV providers.

Command attributes:
  Session: Required
  Destructive: No

  INFO DCV <provider-name>
  INFO DCV *

Command target:

<provider-name> | *

  The DCV provider name, or * for all providers.

Output options:

DETAIL

  Accepted with the normal provider information.

Command: ADD DCV-AZURE

ADD DCV-AZURE Command

Creates an Azure DNS DCV provider.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD DCV-AZURE <provider-name>, CLIENT-ID <credential-name>, CLIENT-SECRET
  <credential-name>, TENANT-ID <tenant-id>, SUBSCRIPTION-ID <subscription-id>,
  RESOURCE-GROUP <resource-group>, ZONE <dns-zone> [ , AUTHORITY-ENDPOINT
  <url> ] [ , MANAGEMENT-ENDPOINT <url> ] [ , TTL <seconds> ]

Command target:

<provider-name>

  The DCV provider name.

Properties:

CLIENT-ID <credential-name>

  The credential containing the Entra application client identifier.

CLIENT-SECRET <credential-name>

  The credential containing the Entra application client secret.

TENANT-ID <tenant-id>

  The Entra tenant identifier.

SUBSCRIPTION-ID <subscription-id>

  The Azure subscription identifier.

RESOURCE-GROUP <resource-group>

  The Azure resource group name.

ZONE <dns-zone>

  The Azure public DNS zone name.

AUTHORITY-ENDPOINT <url>

  The optional Entra authority override.

MANAGEMENT-ENDPOINT <url>

  The optional Azure API override.

TTL <seconds>

  The DNS record lifetime.

Command: ALTER DCV-AZURE

ALTER DCV-AZURE Command

Changes an Azure DNS DCV provider.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER DCV-AZURE <provider-name>
        [ , NAME <new-name> ]
        [ , CLIENT-ID <credential-name> ]
        [ , CLIENT-SECRET <credential-name> ]
        [ , TENANT-ID <tenant-id> ]
        [ , SUBSCRIPTION-ID <subscription-id> ]
        [ , RESOURCE-GROUP <resource-group> ]
        [ , ZONE <dns-zone> ]
        [ , AUTHORITY-ENDPOINT <url> ]
        [ , MANAGEMENT-ENDPOINT <url> ]
        [ , TTL <seconds> ]
        [ , ENABLED ON | OFF ]

Command target:

<provider-name>

  The DCV provider name.

Properties:

NAME <new-name>

  The new DCV provider name.

CLIENT-ID <credential-name>

  The credential containing the Entra application client identifier.

CLIENT-SECRET <credential-name>

  The credential containing the Entra application client secret.

TENANT-ID <tenant-id>

  The Entra tenant identifier.

SUBSCRIPTION-ID <subscription-id>

  The Azure subscription identifier.

RESOURCE-GROUP <resource-group>

  The Azure resource group name.

ZONE <dns-zone>

  The Azure public DNS zone name.

AUTHORITY-ENDPOINT <url>

  The optional Entra authority override.

MANAGEMENT-ENDPOINT <url>

  The optional Azure API override.

TTL <seconds>

  The DNS record lifetime.

ENABLED ON | OFF

  Controls whether the provider may be used.

Command: DELETE DCV-AZURE

DELETE DCV-AZURE Command

Deletes an unreferenced Azure DNS DCV provider.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE DCV-AZURE <provider-name>

Command target:

<provider-name>

  The DCV provider name.

Command: INFO DCV-AZURE

INFO DCV-AZURE Command

Displays an Azure DNS DCV provider.

Command attributes:
  Session: Required
  Destructive: No

  INFO DCV-AZURE <provider-name>
       [ , DETAIL ]

Command target:

<provider-name>

  The DCV provider name.

Output options:

DETAIL

  Accepted with the normal provider information.

Command: VERIFY DCV-AZURE

VERIFY DCV-AZURE Command

Submits Azure DNS access and zone verification.

Command attributes:
  Session: Required
  Destructive: No

  VERIFY DCV-AZURE <provider-name>
         [ , WAIT ]

Command target:

<provider-name>

  The DCV provider name.

Action options:

WAIT

  Waits up to five minutes for verification completion. A timeout leaves the
  task active; inspect the reported Task Handle with INFO TASK or continue
  with WAIT TASK.

Command: ADD DCV-DESEC

ADD DCV-DESEC Command

Creates a deSEC DNS DCV provider.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD DCV-DESEC <provider-name>, API-TOKEN <credential-name>, ZONE <dns-zone>
  [ , API-ENDPOINT <url> ] [ , TTL <seconds> ]

Command target:

<provider-name>

  The DCV provider name.

Properties:

API-TOKEN <credential-name>

  The credential containing the deSEC API token.

ZONE <dns-zone>

  The deSEC public DNS zone name.

API-ENDPOINT <url>

  The optional deSEC API endpoint override.

TTL <seconds>

  The DNS record lifetime.

Command: ALTER DCV-DESEC

ALTER DCV-DESEC Command

Changes a deSEC DNS DCV provider.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER DCV-DESEC <provider-name>
        [ , NAME <new-name> ]
        [ , API-TOKEN <credential-name> ]
        [ , ZONE <dns-zone> ]
        [ , API-ENDPOINT <url> ]
        [ , TTL <seconds> ]
        [ , ENABLED ON | OFF ]

Command target:

<provider-name>

  The DCV provider name.

Properties:

NAME <new-name>

  The new DCV provider name.

API-TOKEN <credential-name>

  The credential containing the deSEC API token.

ZONE <dns-zone>

  The deSEC public DNS zone name.

API-ENDPOINT <url>

  The optional deSEC API endpoint override.

TTL <seconds>

  The DNS record lifetime.

ENABLED ON | OFF

  Controls whether the provider may be used.

Command: DELETE DCV-DESEC

DELETE DCV-DESEC Command

Deletes an unreferenced deSEC DNS DCV provider.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE DCV-DESEC <provider-name>

Command target:

<provider-name>

  The DCV provider name.

Command: INFO DCV-DESEC

INFO DCV-DESEC Command

Displays a deSEC DNS DCV provider.

Command attributes:
  Session: Required
  Destructive: No

  INFO DCV-DESEC <provider-name>
       [ , DETAIL ]

Command target:

<provider-name>

  The DCV provider name.

Output options:

DETAIL

  Accepted with the normal provider information.

Command: VERIFY DCV-DESEC

VERIFY DCV-DESEC Command

Submits deSEC DNS access and zone verification.

Command attributes:
  Session: Required
  Destructive: No

  VERIFY DCV-DESEC <provider-name>
         [ , WAIT ]

Command target:

<provider-name>

  The DCV provider name.

Action options:

WAIT

  Waits up to five minutes for verification completion. A timeout leaves the
  task active; inspect the reported Task Handle with INFO TASK or continue
  with WAIT TASK.

Command: ADD DCV-ROUTE53

ADD DCV-ROUTE53 Command

Creates a Route 53 DCV provider.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD DCV-ROUTE53 <provider-name>, ACCESS-KEY-ID <credential-name>,
  SECRET-ACCESS-KEY <credential-name> [ , SESSION-TOKEN <credential-name> ] [
  , REGION <region> ] [ , ENDPOINT <url> ], HOSTED-ZONE-ID <zone-id> [ , TTL
  <seconds> ]

Command target:

<provider-name>

  The DCV provider name.

Properties:

ACCESS-KEY-ID <credential-name>

  The credential containing the AWS access key identifier.

SECRET-ACCESS-KEY <credential-name>

  The credential containing the AWS secret access key.

SESSION-TOKEN <credential-name>

  The optional credential containing the AWS session token.

REGION <region>

  The AWS region.

ENDPOINT <url>

  The Route 53 API endpoint override.

HOSTED-ZONE-ID <zone-id>

  The Route 53 hosted zone identifier.

TTL <seconds>

  The DNS record lifetime.

Command: ALTER DCV-ROUTE53

ALTER DCV-ROUTE53 Command

Changes a Route 53 DCV provider.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER DCV-ROUTE53 <provider-name> [ , NAME <new-name> ] [ , ACCESS-KEY-ID
  <credential-name>, SECRET-ACCESS-KEY <credential-name> ] [ , SESSION-TOKEN
  <credential-name> ] [ , REGION <region> ] [ , ENDPOINT <url> ] [ ,
  HOSTED-ZONE-ID <zone-id> ] [ , TTL <seconds> ] [ , ENABLED ON | OFF ]

Command target:

<provider-name>

  The DCV provider name.

Properties:

NAME <new-name>

  The new DCV provider name.

ACCESS-KEY-ID <credential-name>

  The credential containing the AWS access key identifier.

SECRET-ACCESS-KEY <credential-name>

  The credential containing the AWS secret access key.

SESSION-TOKEN <credential-name>

  The optional credential containing the AWS session token.

REGION <region>

  The AWS region.

ENDPOINT <url>

  The Route 53 API endpoint override.

HOSTED-ZONE-ID <zone-id>

  The Route 53 hosted zone identifier.

TTL <seconds>

  The DNS record lifetime.

ENABLED ON | OFF

  Controls whether the provider may be used.

Command: DELETE DCV-ROUTE53

DELETE DCV-ROUTE53 Command

Deletes an unreferenced Route 53 DCV provider.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE DCV-ROUTE53 <provider-name>

Command target:

<provider-name>

  The DCV provider name.

Command: INFO DCV-ROUTE53

INFO DCV-ROUTE53 Command

Displays one or more Route 53 DCV providers.

Command attributes:
  Session: Required
  Destructive: No

  INFO DCV-ROUTE53 <provider-name> [ , DETAIL ]
  INFO DCV-ROUTE53 * [ , ENABLED | DISABLED ]

Command target:

<provider-name> | *

  The DCV provider name, or * for all Route 53 providers.

Selection filters:

ENABLED

  Selects enabled providers.

DISABLED

  Selects disabled providers.

Output options:

DETAIL

  Displays provider configuration, transport status, and diagnostics.

Command: VERIFY DCV-ROUTE53

VERIFY DCV-ROUTE53 Command

Submits Route 53 access and hosted-zone verification.

Command attributes:
  Session: Required
  Destructive: No

  VERIFY DCV-ROUTE53 <provider-name>
         [ , WAIT ]

Command target:

<provider-name>

  The DCV provider name.

Action options:

WAIT

  Waits up to five minutes for verification completion. A timeout leaves the
  task active; inspect the reported Task Handle with INFO TASK or continue
  with WAIT TASK.

Command: INFO DEPLOYMENT

INFO DEPLOYMENT Command

Displays one or more deployment attempts.
Timestamps use whole-second UTC
display without rounding.

Command attributes:
  Session: Required
  Destructive: No

  INFO DEPLOYMENT <deployment-handle> [ , DETAIL ]
  INFO DEPLOYMENT * [ , TARGET <target-name> ] [ , CERTIFICATE
  <certificate-name> [ , VERSION <number> ] ] [ , TYPE DEPLOY | VERIFY |
  ROLLBACK ] [ , STATUS PENDING | RUNNING | VERIFYING | COMPLETED | FAILED |
  ABORTED | OPERATOR-ACTION ] [ , RECENT <count> ]

Command target:

<deployment-handle> | *

  The deployment attempt handle, or * for all attempts.

Selection filters:

TARGET <target-name>

  Selects one deployment target.

CERTIFICATE <certificate-name>

  Selects one managed certificate.

VERSION <number>

  Selects a version number within the certificate.

TYPE DEPLOY | VERIFY | ROLLBACK

  Selects deployment attempts by operation type.

STATUS PENDING | RUNNING | VERIFYING | COMPLETED | FAILED | ABORTED | OPERATOR-ACTION

  Selects deployment attempts by status.

Output options:

DETAIL

  Displays additional deployment information.

RECENT <count>

  Limits output to recent attempts.

Command: ADD DEPLOYMENT-WINDOW

ADD DEPLOYMENT-WINDOW Command

Creates a deployment maintenance window.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD DEPLOYMENT-WINDOW <window-name>
      , DAYS <SUN,MON,... | ALL>
      , START <HH:MM>
      , DURATION-MINUTES <minutes>

Command target:

<window-name>

  The deployment window name.

Properties:

DAYS <SUN,MON,... | ALL>

  Selected UTC weekdays, supplied as a quoted comma-separated value.

START <HH:MM>

  The UTC start time.

DURATION-MINUTES <minutes>

  The window duration in minutes.

Command: ALTER DEPLOYMENT-WINDOW

ALTER DEPLOYMENT-WINDOW Command

Changes a deployment maintenance window.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER DEPLOYMENT-WINDOW <window-name>
        [ , NAME <new-name> ]
        [ , DAYS <SUN,MON,... | ALL> ]
        [ , START <HH:MM> ]
        [ , DURATION-MINUTES <minutes> ]
        [ , ENABLED ON | OFF ]

Command target:

<window-name>

  The deployment window name.

Properties:

NAME <new-name>

  The new deployment window name.

DAYS <SUN,MON,... | ALL>

  Selected UTC weekdays, supplied as a quoted comma-separated value.

START <HH:MM>

  The UTC start time.

DURATION-MINUTES <minutes>

  The window duration in minutes.

ENABLED ON | OFF

  Controls whether deployments may use the window.

Command: DELETE DEPLOYMENT-WINDOW

DELETE DEPLOYMENT-WINDOW Command

Deletes a disabled, unreferenced deployment window.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE DEPLOYMENT-WINDOW <window-name>

Command target:

<window-name>

  The deployment window name.

Command: INFO DEPLOYMENT-WINDOW

INFO DEPLOYMENT-WINDOW Command

Displays deployment maintenance windows.

Command attributes:
  Session: Required
  Destructive: No

  INFO DEPLOYMENT-WINDOW <window-name> [ , DETAIL ]
  INFO DEPLOYMENT-WINDOW * [ , ENABLED | DISABLED ]

Command target:

<window-name> | *

  The deployment window name, or * for all windows.

Selection filters:

ENABLED

  Selects enabled windows.

DISABLED

  Selects disabled windows.

Output options:

DETAIL

  Displays deployment window configuration.

Command: EXPORT EVENT

EXPORT EVENT Command

Exports event records as structured data.

The export includes event identifiers, time, severity, component, message,
related object identifiers, and diagnostic reference. CSV is used when FORMAT
is omitted.

Command attributes:
  Session: Required
  Destructive: Yes

  EXPORT EVENT <event-handle>, FILE <guardian-file> [ ! ] [ , FORMAT CSV |
  JSON-LINES ]
  EXPORT EVENT *, FILE <guardian-file> [ ! ] [ , FORMAT CSV | JSON-LINES ] [ ,
  RECENT <count> ] [ , SEVERITY INFO | WARNING | ERROR ]

Command target:

<event-handle> | *

  The event handle, or * for all events.

Selection filters:

SEVERITY INFO | WARNING | ERROR

  Selects events by severity.

Output options:

FILE <guardian-file> [ ! ]

  The Guardian export file.

FORMAT CSV | JSON-LINES

  The structured event export format. If omitted, the default value is "CSV".

RECENT <count>

  Limits output to recent events.

Command: INFO EVENT

INFO EVENT Command

Displays one or more event records.

An event handle displays complete event information. An asterisk displays a
compact event table.

Command attributes:
  Session: Required
  Destructive: No

  INFO EVENT <event-handle> [ , DETAIL ]
  INFO EVENT * [ , RECENT <count> ] [ , SEVERITY INFO | WARNING | ERROR ]

Command target:

<event-handle> | *

  The event handle, or * for all events.

Selection filters:

SEVERITY INFO | WARNING | ERROR

  Selects events by severity.

Output options:

DETAIL

  Accepted with the normal event information.

RECENT <count>

  Limits output to recent events.

Command: ADD ISSUER

ADD ISSUER Command

Creates a certificate issuer.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD ISSUER <issuer-name>, TYPE TEST-CA
  ADD ISSUER <issuer-name>, TYPE ACME, DIRECTORY <url>, DCV ( EXTERNAL |
  <provider-name> ), ( ACCOUNT-KEY <credential-name> | GENERATE-ACCOUNT-KEY )
  [ , CONTACT <contact> ] [ , EAB-KEY-ID <key-id> ] [ , EAB-CREDENTIAL
  <credential-name> ] [ , TRUST-ANCHOR <guardian-file> ] [ , PROXY <url> ] [ ,
  CONNECT-TIMEOUT <seconds> ] [ , READ-TIMEOUT <seconds> ]

Command target:

<issuer-name>

  The issuer name.

Properties:

TYPE TEST-CA | ACME

  The issuer type.

DIRECTORY <url>

  The ACME directory URL.

DCV EXTERNAL | <provider-name>

  The external or named DCV provider used for ACME authorization.

ACCOUNT-KEY <credential-name>

  The ACME account key credential.

GENERATE-ACCOUNT-KEY

  Records intent to generate a protected ACME account key.

CONTACT <contact>

  An ACME account contact.

EAB-KEY-ID <key-id>

  The external account binding key identifier.

EAB-CREDENTIAL <credential-name>

  The EAB-SECRET credential containing the CA-provided base64url HMAC.

TRUST-ANCHOR <guardian-file>

  The TLS trust anchor file.

PROXY <url>

  The HTTP proxy URL.

CONNECT-TIMEOUT <seconds>

  The connection timeout in seconds.

READ-TIMEOUT <seconds>

  The read timeout in seconds.

Command: ALTER ISSUER

ALTER ISSUER Command

Changes a certificate issuer.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER ISSUER <issuer-name>
        [ , NAME <new-name> ]
        [ , DIRECTORY <url> ]
        [ , DCV EXTERNAL | <provider-name> ]
        [ , ACCOUNT-KEY <credential-name> ]
        [ , GENERATE-ACCOUNT-KEY ]
        [ , CONTACT <contact> ]
        [ , EAB-KEY-ID <key-id> ]
        [ , EAB-CREDENTIAL <credential-name> ]
        [ , TRUST-ANCHOR <guardian-file> ]
        [ , PROXY <url> ]
        [ , CONNECT-TIMEOUT <seconds> ]
        [ , READ-TIMEOUT <seconds> ]
        [ , ENABLED ON | OFF ]

Command target:

<issuer-name>

  The issuer name.

Properties:

NAME <new-name>

  The new issuer name.

DIRECTORY <url>

  The ACME directory URL.

DCV EXTERNAL | <provider-name>

  The external or named DCV provider used for ACME authorization.

ACCOUNT-KEY <credential-name>

  The ACME account key credential.

GENERATE-ACCOUNT-KEY

  Records intent to generate a protected ACME account key.

CONTACT <contact>

  An ACME account contact.

EAB-KEY-ID <key-id>

  The external account binding key identifier.

EAB-CREDENTIAL <credential-name>

  The EAB-SECRET credential containing the CA-provided base64url HMAC.

TRUST-ANCHOR <guardian-file>

  The TLS trust anchor file.

PROXY <url>

  The HTTP proxy URL.

CONNECT-TIMEOUT <seconds>

  The connection timeout in seconds.

READ-TIMEOUT <seconds>

  The read timeout in seconds.

ENABLED ON | OFF

  Controls whether the issuer may be used.

Command: DELETE ISSUER

DELETE ISSUER Command

Deletes a disabled, unreferenced certificate issuer.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE ISSUER <issuer-name>

Command target:

<issuer-name>

  The issuer name.

Command: INFO ISSUER

INFO ISSUER Command

Displays one or more certificate issuers.

Command attributes:
  Session: Required
  Destructive: No

  INFO ISSUER <issuer-name> [ , DETAIL ]
  INFO ISSUER * [ , TYPE TEST-CA | ACME ] [ , ENABLED | DISABLED ]

Command target:

<issuer-name> | *

  The issuer name, or * for all issuers.

Selection filters:

TYPE TEST-CA | ACME

  The issuer type.

ENABLED

  Selects enabled issuers.

DISABLED

  Selects disabled issuers.

Output options:

DETAIL

  Displays issuer configuration and diagnostics.

Command: VERIFY ISSUER

VERIFY ISSUER Command

Submits certificate issuer verification work.

Command attributes:
  Session: Required
  Destructive: No

  VERIFY ISSUER <issuer-name>
         [ , WAIT ]

Command target:

<issuer-name>

  The issuer name.

Action options:

WAIT

  Waits for submitted verification work.

Command: ADD KEY-POLICY

ADD KEY-POLICY Command

Creates a certificate key policy.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD KEY-POLICY <policy-name>
      , SOURCE GENERATE | IMPORT | REUSE-CURRENT
      , ALGORITHM RSA | ECDSA
      [ , SIZE <bits> ]
      [ , CURVE <curve-name> ]
      [ , ROTATE-ON-RENEW ON | OFF ]
      [ , PRIVATE-KEY <credential-name> ]

Command target:

<policy-name>

  The key policy name.

Properties:

SOURCE GENERATE | IMPORT | REUSE-CURRENT

  The private key source.

ALGORITHM RSA | ECDSA

  The private key algorithm.

SIZE <bits>

  The RSA key size.

CURVE <curve-name>

  The ECDSA curve.

ROTATE-ON-RENEW ON | OFF

  Controls key rotation for SOURCE GENERATE during renewal.

PRIVATE-KEY <credential-name>

  Selects the PRIVATE-KEY credential required by SOURCE IMPORT.

Command: ALTER KEY-POLICY

ALTER KEY-POLICY Command

Changes a certificate key policy.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER KEY-POLICY <policy-name>
        [ , NAME <new-name> ]
        [ , SOURCE GENERATE | IMPORT | REUSE-CURRENT ]
        [ , ALGORITHM RSA | ECDSA ]
        [ , SIZE <bits> ]
        [ , CURVE <curve-name> ]
        [ , ROTATE-ON-RENEW ON | OFF ]
        [ , PRIVATE-KEY <credential-name> ]
        [ , ENABLED ON | OFF ]

Command target:

<policy-name>

  The key policy name.

Properties:

NAME <new-name>

  The new key policy name.

SOURCE GENERATE | IMPORT | REUSE-CURRENT

  The private key source.

ALGORITHM RSA | ECDSA

  The private key algorithm.

SIZE <bits>

  The RSA key size.

CURVE <curve-name>

  The ECDSA curve.

ROTATE-ON-RENEW ON | OFF

  Controls key rotation for SOURCE GENERATE during renewal.

PRIVATE-KEY <credential-name>

  Selects the PRIVATE-KEY credential required by SOURCE IMPORT.

ENABLED ON | OFF

  Controls whether the key policy may be used.

Command: DELETE KEY-POLICY

DELETE KEY-POLICY Command

Deletes an unreferenced certificate key policy.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE KEY-POLICY <policy-name>

Command target:

<policy-name>

  The key policy name.

Command: INFO KEY-POLICY

INFO KEY-POLICY Command

Displays one or more certificate key policies.

Command attributes:
  Session: Required
  Destructive: No

  INFO KEY-POLICY <policy-name> [ , DETAIL ]
  INFO KEY-POLICY * [ , ENABLED | DISABLED ]

Command target:

<policy-name> | *

  The key policy name, or * for all policies.

Selection filters:

ENABLED

  Selects enabled key policies.

DISABLED

  Selects disabled key policies.

Output options:

DETAIL

  Displays key policy configuration.

Command: VALIDATE LICENSE

VALIDATE LICENSE Command

Validates an ActivCERT license before installation.

Command attributes:
  Session: Not required
  Destructive: No

  VALIDATE LICENSE <guardian-file>

Command target:

<guardian-file>

  The signed ActivCERT license file to validate.

Command: STATUS MONITOR

STATUS MONITOR Command

Displays the state of the connected ActivCERT monitor.

Command attributes:
  Session: Required
  Destructive: No

  STATUS MONITOR
         [ , DETAIL ]

Output options:

DETAIL

  Displays additional information.

Command: STOP MONITOR

STOP MONITOR Command

Stops the connected ActivCERT monitor.

Command attributes:
  Session: Required
  Destructive: Yes

  STOP MONITOR [ , DRAIN | NOW ]

Action options:

DRAIN

  Allows active work to finish before CERTMON stops.

NOW

  Stops CERTMON without waiting for active work.

Command: STATUS PROCESS

STATUS PROCESS Command

Displays ActivCERT process status.

Reports the monitor pair and active worker processes, including Guardian
identity, task ownership, liveness, and configured worker slot consumption.

Command attributes:
  Session: Required
  Destructive: No

  STATUS PROCESS <logical-name> | *
         [ , DETAIL ]

Command target:

<logical-name> | *

  The Guardian logical process name, or * for all processes.

Output options:

DETAIL

  Displays the last scheduler scan time.

Command: CLEAN RECORDS

CLEAN RECORDS Command

Removes expired unreferenced ActivCERT datastore records.

Command attributes:
  Session: Required
  Destructive: Yes

  CLEAN RECORDS
        [ , PREVIEW ]

Action options:

PREVIEW

  Reports eligible records without removing them.

Command: ADD RENEWAL-POLICY

ADD RENEWAL-POLICY Command

Creates a certificate renewal policy.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD RENEWAL-POLICY <policy-name>
      , RENEW-BEFORE <duration>
      [ , USE-ARI ON | OFF ]
      [ , RETRY-INTERVAL <duration> ]
      [ , MAX-RETRIES <count> ]
      [ , RANDOM-DELAY <duration> ]
      [ , MANUAL-RENEW ON | OFF ]
      [ , DEPLOY-AFTER-RENEW ON | OFF ]

Command target:

<policy-name>

  The renewal policy name.

Properties:

RENEW-BEFORE <duration>

  The renewal window before expiry. Use unsigned seconds or an S, M, H, D
  suffix (case-insensitive), for example 10d. Maximum 4294967295 seconds; no
  spaces or signs.

USE-ARI ON | OFF

  Controls ACME Renewal Information use.

RETRY-INTERVAL <duration>

  The delay between renewal retries; default 1h. Use unsigned seconds or an S,
  M, H, D suffix (case-insensitive), for example 10d. Maximum 4294967295
  seconds; no spaces or signs.

MAX-RETRIES <count>

  The maximum renewal retry count.

RANDOM-DELAY <duration>

  The scheduler spread applied to renewal; default 15m. Use unsigned seconds
  or an S, M, H, D suffix (case-insensitive), for example 10d. Maximum
  4294967295 seconds; no spaces or signs.

MANUAL-RENEW ON | OFF

  Controls manual renewal permission.

DEPLOY-AFTER-RENEW ON | OFF

  Controls deployment after renewal.

Command: ALTER RENEWAL-POLICY

ALTER RENEWAL-POLICY Command

Changes a certificate renewal policy.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER RENEWAL-POLICY <policy-name>
        [ , NAME <new-name> ]
        [ , RENEW-BEFORE <duration> ]
        [ , USE-ARI ON | OFF ]
        [ , RETRY-INTERVAL <duration> ]
        [ , MAX-RETRIES <count> ]
        [ , RANDOM-DELAY <duration> ]
        [ , MANUAL-RENEW ON | OFF ]
        [ , DEPLOY-AFTER-RENEW ON | OFF ]

Command target:

<policy-name>

  The renewal policy name.

Properties:

NAME <new-name>

  The new renewal policy name.

RENEW-BEFORE <duration>

  The renewal window before expiry. Use unsigned seconds or an S, M, H, D
  suffix (case-insensitive), for example 10d. Maximum 4294967295 seconds; no
  spaces or signs.

USE-ARI ON | OFF

  Controls ACME Renewal Information use.

RETRY-INTERVAL <duration>

  The delay between renewal retries; default 1h. Use unsigned seconds or an S,
  M, H, D suffix (case-insensitive), for example 10d. Maximum 4294967295
  seconds; no spaces or signs.

MAX-RETRIES <count>

  The maximum renewal retry count.

RANDOM-DELAY <duration>

  The scheduler spread applied to renewal; default 15m. Use unsigned seconds
  or an S, M, H, D suffix (case-insensitive), for example 10d. Maximum
  4294967295 seconds; no spaces or signs.

MANUAL-RENEW ON | OFF

  Controls manual renewal permission.

DEPLOY-AFTER-RENEW ON | OFF

  Controls deployment after renewal.

Command: DELETE RENEWAL-POLICY

DELETE RENEWAL-POLICY Command

Deletes an unreferenced certificate renewal policy.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE RENEWAL-POLICY <policy-name>

Command target:

<policy-name>

  The renewal policy name.

Command: INFO RENEWAL-POLICY

INFO RENEWAL-POLICY Command

Displays one or more certificate renewal policies.

Command attributes:
  Session: Required
  Destructive: No

  INFO RENEWAL-POLICY <policy-name> [ , DETAIL ]
  INFO RENEWAL-POLICY *

Command target:

<policy-name> | *

  The renewal policy name, or * for all policies.

Output options:

DETAIL

  Displays renewal policy configuration.

Command: ALTER SCHEDULER

ALTER SCHEDULER Command

Changes scheduler configuration properties.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER SCHEDULER
        , INTERVAL <seconds>

Properties:

INTERVAL <seconds>

  The interval between scheduler runs.

Command: FREEZE SCHEDULER

FREEZE SCHEDULER Command

Stops the scheduler from creating work.

Command attributes:
  Session: Required
  Destructive: Yes

  FREEZE SCHEDULER
         [ , REASON <text> ]

Action options:

REASON <text>

  Records the scheduler freeze reason.

Command: STATUS SCHEDULER

STATUS SCHEDULER Command

Displays scheduler state and last/next scan times in UTC. Last Scan is the
start time of the last completed scan; NOT RUN precedes the first scan of the
current monitor. Last Scan is UNAVAILABLE without a current monitor runtime
record. Next Scan is NONE while frozen or stopped, or UNAVAILABLE when no
planned time is recorded.

Command attributes:
  Session: Required
  Destructive: No

  STATUS SCHEDULER
         [ , DETAIL ]

Output options:

DETAIL

  Displays the last scan result and certificate counts.

Command: THAW SCHEDULER

THAW SCHEDULER Command

Allows the scheduler to create work.

Command attributes:
  Session: Required
  Destructive: Yes

  THAW SCHEDULER

Command: STATUS SESSION

STATUS SESSION Command

Displays the state of the CERTCOM session.

Command attributes:
  Session: Not required
  Destructive: No

  STATUS SESSION

Command: DEPLOY TARGET

DEPLOY TARGET Command

Submits deployment work for one target.

Command attributes:
  Session: Required
  Destructive: Yes

  DEPLOY TARGET <target-name>
         [ , VERSION <number> ]
         [ , OVERRIDE-WINDOW ]
         [ , WAIT ]

Command target:

<target-name>

  The deployment target name.

Action options:

VERSION <number>

  Selects a version number within the certificate.

OVERRIDE-WINDOW

  Starts the deployment outside its configured maintenance window.

WAIT

  Waits for submitted deployment work.

Command: INFO TARGET

INFO TARGET Command

Displays one or more deployment target configurations.

Command attributes:
  Session: Required
  Destructive: No

  INFO TARGET <target-name> [ , DETAIL ]
  INFO TARGET * [ , CERTIFICATE <certificate-name> ] [ , TYPE FILE | LW ] [ ,
  ENABLED | DISABLED ]

Command target:

<target-name> | *

  The deployment target name, or * for all targets.

Selection filters:

CERTIFICATE <certificate-name>

  Selects targets for one managed certificate.

TYPE FILE | LW

  Selects targets by deployment type.

ENABLED

  Selects enabled entries.

DISABLED

  Selects disabled entries.

Output options:

DETAIL

  Displays target configuration or state details.

Command: ROLLBACK TARGET

ROLLBACK TARGET Command

Submits target rollback work.

Command attributes:
  Session: Required
  Destructive: Yes

  ROLLBACK TARGET <target-name>
           [ , OVERRIDE-WINDOW ]
           [ , WAIT ]

Command target:

<target-name>

  The deployment target name.

Action options:

OVERRIDE-WINDOW

  Starts the deployment outside its configured maintenance window.

WAIT

  Waits for submitted deployment work.

Command: STATUS TARGET

STATUS TARGET Command

Displays dynamic deployment target state.

Command attributes:
  Session: Required
  Destructive: No

  STATUS TARGET <target-name> [ , DETAIL ]
  STATUS TARGET * [ , CERTIFICATE <certificate-name> ] [ , TYPE FILE | LW ] [
  , ENABLED | DISABLED ]

Command target:

<target-name> | *

  The deployment target name, or * for all targets.

Selection filters:

CERTIFICATE <certificate-name>

  Selects targets for one managed certificate.

TYPE FILE | LW

  Selects targets by deployment type.

ENABLED

  Selects enabled entries.

DISABLED

  Selects disabled entries.

Output options:

DETAIL

  Displays target configuration or state details.

Command: VERIFY TARGET

VERIFY TARGET Command

Submits target verification work.

Command attributes:
  Session: Required
  Destructive: No

  VERIFY TARGET <target-name>
         [ , OVERRIDE-WINDOW ]
         [ , WAIT ]

Command target:

<target-name>

  The deployment target name.

Action options:

OVERRIDE-WINDOW

  Starts the deployment outside its configured maintenance window.

WAIT

  Waits for submitted deployment work.

Command: ADD TARGET-FILE

ADD TARGET-FILE Command

Creates a Guardian file deployment target.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD TARGET-FILE <target-name>, CERTIFICATE <certificate-name>, FORMAT
  PEM-SEPARATE, FILE-TYPE <file-type> [ , REPLACE-MODE <replace-mode> ],
  CERT-FILE <guardian-file>, KEY-FILE <guardian-file> [ , CHAIN-FILE
  <guardian-file> ] [ , FULLCHAIN-FILE <guardian-file> ] ...
  ADD TARGET-FILE <target-name>, CERTIFICATE <certificate-name>, FORMAT
  PEM-FULLCHAIN, FILE-TYPE <file-type> [ , REPLACE-MODE <replace-mode> ],
  FULLCHAIN-FILE <guardian-file>, KEY-FILE <guardian-file> ...
  ADD TARGET-FILE <target-name>, CERTIFICATE <certificate-name>, FORMAT
  PKCS12, FILE-TYPE <file-type> [ , REPLACE-MODE <replace-mode> ], PKCS12-FILE
  <guardian-file>, PASSPHRASE <credential-name> | NO-PASSPHRASE ...

Command target:

<target-name>

  The deployment target name.

Properties:

CERTIFICATE <certificate-name>

  The managed certificate.

FORMAT PEM-SEPARATE | PEM-FULLCHAIN | PKCS12

  The Guardian file target format.

FILE-TYPE EDIT | STREAM | BINARY

  The Guardian target file type.

REPLACE-MODE REPLACE-EXISTING | CREATE-ONLY | REPLACE-OR-CREATE

  The target file replacement policy. Defaults to REPLACE-OR-CREATE on ADD.

DEPLOY-AFTER-RENEW ON | OFF

  Controls deployment after renewal.

VERIFY-AFTER-DEPLOY ON

  Verification is required after deployment.

CAPTURE-BASELINE ON | OFF

  Controls baseline capture before deployment.

ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF

  Allows renewal completion when this target deployment fails.

CERT-FILE <guardian-file>

  The separate PEM certificate file.

KEY-FILE <guardian-file>

  The separate PEM private key file.

CHAIN-FILE <guardian-file>

  The separate PEM chain file.

FULLCHAIN-FILE <guardian-file>

  The full-chain PEM file.

PKCS12-FILE <guardian-file>

  The PKCS12 output file.

PASSPHRASE <credential-name>

  The PKCS12 passphrase credential.

NO-PASSPHRASE

  Creates PKCS12 output without a passphrase.

REQUIRE-EXISTING ON | OFF

  Controls validation of missing target files.

WINDOW <window-name>

  Assigns a deployment maintenance window.

Command: ALTER TARGET-FILE

ALTER TARGET-FILE Command

Changes a Guardian file deployment target.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER TARGET-FILE <target-name>
        [ , NAME <new-name> ]
        [ , CERTIFICATE <certificate-name> ]
        [ , FORMAT PEM-SEPARATE | PEM-FULLCHAIN | PKCS12 ]
        [ , FILE-TYPE EDIT | STREAM | BINARY ]
        [ , REPLACE-MODE REPLACE-EXISTING | CREATE-ONLY | REPLACE-OR-CREATE ]
        [ , DEPLOY-AFTER-RENEW ON | OFF ]
        [ , VERIFY-AFTER-DEPLOY ON ]
        [ , CAPTURE-BASELINE ON | OFF ]
        [ , ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF ]
        [ , CERT-FILE <guardian-file> ]
        [ , KEY-FILE <guardian-file> ]
        [ , CHAIN-FILE <guardian-file> ]
        [ , FULLCHAIN-FILE <guardian-file> ]
        [ , PKCS12-FILE <guardian-file> ]
        [ , PASSPHRASE <credential-name> ]
        [ , NO-PASSPHRASE ]
        [ , REQUIRE-EXISTING ON | OFF ]
        [ , ENABLED ON | OFF ]
        [ , WINDOW <window-name> ]
        [ , NO-WINDOW ]

Command target:

<target-name>

  The deployment target name.

Properties:

NAME <new-name>

  The new deployment target name.

CERTIFICATE <certificate-name>

  The managed certificate.

FORMAT PEM-SEPARATE | PEM-FULLCHAIN | PKCS12

  The Guardian file target format.

FILE-TYPE EDIT | STREAM | BINARY

  The Guardian target file type.

REPLACE-MODE REPLACE-EXISTING | CREATE-ONLY | REPLACE-OR-CREATE

  The target file replacement policy. Defaults to REPLACE-OR-CREATE on ADD.

DEPLOY-AFTER-RENEW ON | OFF

  Controls deployment after renewal.

VERIFY-AFTER-DEPLOY ON

  Verification is required after deployment.

CAPTURE-BASELINE ON | OFF

  Controls baseline capture before deployment.

ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF

  Allows renewal completion when this target deployment fails.

CERT-FILE <guardian-file>

  The separate PEM certificate file.

KEY-FILE <guardian-file>

  The separate PEM private key file.

CHAIN-FILE <guardian-file>

  The separate PEM chain file.

FULLCHAIN-FILE <guardian-file>

  The full-chain PEM file.

PKCS12-FILE <guardian-file>

  The PKCS12 output file.

PASSPHRASE <credential-name>

  The PKCS12 passphrase credential.

NO-PASSPHRASE

  Creates PKCS12 output without a passphrase.

REQUIRE-EXISTING ON | OFF

  Controls validation of missing target files.

ENABLED ON | OFF

  Controls whether the target may be used.

WINDOW <window-name>

  Assigns a deployment maintenance window.

NO-WINDOW

  Removes the deployment maintenance window.

Command: DELETE TARGET-FILE

DELETE TARGET-FILE Command

Deletes an unreferenced Guardian file deployment target.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE TARGET-FILE <target-name>

Command target:

<target-name>

  The deployment target name.

Command: INFO TARGET-FILE

INFO TARGET-FILE Command

Displays one or more Guardian file deployment targets.

Command attributes:
  Session: Required
  Destructive: No

  INFO TARGET-FILE <target-name> [ , DETAIL ]
  INFO TARGET-FILE * [ , CERTIFICATE <certificate-name> ] [ , ENABLED |
  DISABLED ]

Command target:

<target-name> | *

  The deployment target name, or * for all targets.

Selection filters:

CERTIFICATE <certificate-name>

  Selects targets for one managed certificate.

ENABLED

  Selects enabled entries.

DISABLED

  Selects disabled entries.

Output options:

DETAIL

  Displays target configuration or state details.

Command: ADD TARGET-LW

ADD TARGET-LW Command

Creates a LightWave command deployment target.

Command attributes:
  Session: Required
  Destructive: Yes

  ADD TARGET-LW <target-name>
      , CERTIFICATE <certificate-name>
      , CERT-SPEC <certificate-spec>
      , PROGRAM-FILE <guardian-file>
      , PASSPHRASE <credential-name>
      [ , COMMON-NAME <common-name> ]
      [ , IMPORT-CHAIN ON | OFF ]
      [ , EXPORT-CHAIN ON | OFF ]
      [ , DEPLOY-AFTER-RENEW ON | OFF ]
      [ , VERIFY-AFTER-DEPLOY ON ]
      [ , CAPTURE-BASELINE ON | OFF ]
      [ , ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF ]
      [ , WINDOW <window-name> ]

Command target:

<target-name>

  The deployment target name.

Properties:

CERTIFICATE <certificate-name>

  The managed certificate.

CERT-SPEC <certificate-spec>

  The LWxCOM certificate specification.

PROGRAM-FILE <guardian-file>

  The fully qualified LWSCOM or LWCCOM program file.

PASSPHRASE <credential-name>

  The PKCS12 passphrase credential.

COMMON-NAME <common-name>

  Display metadata for the target.

IMPORT-CHAIN ON | OFF

  Controls chain import through LWxCOM.

EXPORT-CHAIN ON | OFF

  Controls chain export through LWxCOM.

DEPLOY-AFTER-RENEW ON | OFF

  Controls deployment after renewal.

VERIFY-AFTER-DEPLOY ON

  Verification is required after deployment.

CAPTURE-BASELINE ON | OFF

  Controls baseline capture before deployment.

ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF

  Allows renewal completion when this target deployment fails.

WINDOW <window-name>

  Assigns a deployment maintenance window.

Command: ALTER TARGET-LW

ALTER TARGET-LW Command

Changes a LightWave deployment target.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER TARGET-LW <target-name>
        [ , NAME <new-name> ]
        [ , CERTIFICATE <certificate-name> ]
        [ , CERT-SPEC <certificate-spec> ]
        [ , PROGRAM-FILE <guardian-file> ]
        [ , PASSPHRASE <credential-name> ]
        [ , COMMON-NAME <common-name> ]
        [ , IMPORT-CHAIN ON | OFF ]
        [ , EXPORT-CHAIN ON | OFF ]
        [ , DEPLOY-AFTER-RENEW ON | OFF ]
        [ , VERIFY-AFTER-DEPLOY ON ]
        [ , CAPTURE-BASELINE ON | OFF ]
        [ , ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF ]
        [ , ENABLED ON | OFF ]
        [ , WINDOW <window-name> ]
        [ , NO-WINDOW ]

Command target:

<target-name>

  The deployment target name.

Properties:

NAME <new-name>

  The new deployment target name.

CERTIFICATE <certificate-name>

  The managed certificate.

CERT-SPEC <certificate-spec>

  The LWxCOM certificate specification.

PROGRAM-FILE <guardian-file>

  The fully qualified LWSCOM or LWCCOM program file.

PASSPHRASE <credential-name>

  The PKCS12 passphrase credential.

COMMON-NAME <common-name>

  Display metadata for the target.

IMPORT-CHAIN ON | OFF

  Controls chain import through LWxCOM.

EXPORT-CHAIN ON | OFF

  Controls chain export through LWxCOM.

DEPLOY-AFTER-RENEW ON | OFF

  Controls deployment after renewal.

VERIFY-AFTER-DEPLOY ON

  Verification is required after deployment.

CAPTURE-BASELINE ON | OFF

  Controls baseline capture before deployment.

ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF

  Allows renewal completion when this target deployment fails.

ENABLED ON | OFF

  Controls whether the target may be used.

WINDOW <window-name>

  Assigns a deployment maintenance window.

NO-WINDOW

  Removes the deployment maintenance window.

Command: DELETE TARGET-LW

DELETE TARGET-LW Command

Deletes an unreferenced LightWave deployment target.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE TARGET-LW <target-name>

Command target:

<target-name>

  The deployment target name.

Command: INFO TARGET-LW

INFO TARGET-LW Command

Displays one or more LightWave deployment targets.

Command attributes:
  Session: Required
  Destructive: No

  INFO TARGET-LW <target-name> [ , DETAIL ]
  INFO TARGET-LW * [ , CERTIFICATE <certificate-name> ] [ , ENABLED | DISABLED
  ]

Command target:

<target-name> | *

  The deployment target name, or * for all targets.

Selection filters:

CERTIFICATE <certificate-name>

  Selects targets for one managed certificate.

ENABLED

  Selects enabled entries.

DISABLED

  Selects disabled entries.

Output options:

DETAIL

  Displays target configuration or state details.

Command: ABORT TASK

ABORT TASK Command

Aborts one task or all open product tasks.

An asterisk aborts pending tasks, requests cancellation for claimed or running
tasks, and makes failed tasks unavailable for retry.

Command attributes:
  Session: Required
  Destructive: Yes

  ABORT TASK <task-handle>
  ABORT TASK *

Command target:

<task-handle> | *

  The task handle, or * for all open tasks.

Command: INFO TASK

INFO TASK Command

Displays a task and related records.

A task handle displays complete task information. An asterisk displays a
compact task table.

Command attributes:
  Session: Required
  Destructive: No

  INFO TASK <task-handle> [ , DETAIL ]
  INFO TASK * [ , ACTIVE | PENDING | RUNNING | COMPLETED | ABORTED | FAILED |
  OPERATOR-ACTION | OPEN | RETRY-CLOSED ] [ , RECENT <count> ]

Command target:

<task-handle> | *

  The task handle, or * for all tasks.

Selection filters:

ACTIVE

  Selects pending, claimed, and running tasks.

PENDING

  Selects pending tasks.

RUNNING

  Selects running tasks.

COMPLETED

  Selects completed tasks.

ABORTED

  Selects aborted tasks.

FAILED

  Selects failed tasks.

OPERATOR-ACTION

  Selects tasks requiring operator action.

OPEN

  Selects open tasks.

RETRY-CLOSED

  Selects terminal tasks that are no longer available for retry.

Output options:

DETAIL

  Accepted with the normal task information.

RECENT <count>

  Limits output to recent tasks.

Command: RETRY TASK

RETRY TASK Command

Submits a legal retry for a task.

Command attributes:
  Session: Required
  Destructive: Yes

  RETRY TASK <task-handle>

Command target:

<task-handle>

  The task handle.

Command: STATUS TASK

STATUS TASK Command

Displays the current operational state of a task.

Reports the task type, current status, worker, timing, result, and pending
operator action.

Command attributes:
  Session: Required
  Destructive: No

  STATUS TASK <task-handle>

Command target:

<task-handle>

  The task handle.

Command: WAIT TASK

WAIT TASK Command

Waits for a task to reach a final state.

Command attributes:
  Session: Required
  Destructive: No

  WAIT TASK <task-handle>
       [ , TIMEOUT <seconds> ]

Command target:

<task-handle>

  The task handle.

Action options:

TIMEOUT <seconds>

  Limits how long CERTCOM waits for completion. If omitted, the default value
  is "300".

Command: CREATE TEST-CA

CREATE TEST-CA Command

Creates the built-in non-production certificate authority.

Command attributes:
  Session: Required
  Destructive: Yes

  CREATE TEST-CA
         , COMMON-NAME <text>
         , VALIDITY-DAYS <days>

Properties:

COMMON-NAME <text>

  The test CA common name.

VALIDITY-DAYS <days>

  The test CA validity in days.

Command: DELETE TEST-CA

DELETE TEST-CA Command

Deletes the test CA when no configured resources depend on it.

Command attributes:
  Session: Required
  Destructive: Yes

  DELETE TEST-CA
         , CONFIRM

Action options:

CONFIRM

  Confirms the destructive test CA operation.

Command: EXPORT TEST-CA

EXPORT TEST-CA Command

Exports the public test CA certificate.

Command attributes:
  Session: Required
  Destructive: Yes

  EXPORT TEST-CA, FILE <guardian-file> [ ! ]

Output options:

FILE <guardian-file> [ ! ]

  The Guardian export file.

Command: INFO TEST-CA

INFO TEST-CA Command

Displays the built-in non-production certificate authority.

Command attributes:
  Session: Required
  Destructive: No

  INFO TEST-CA
       [ , DETAIL ]

Output options:

DETAIL

  Displays CA identity and certificate details.

Command: ROTATE TEST-CA

ROTATE TEST-CA Command

Creates a new test CA key and certificate.

Command attributes:
  Session: Required
  Destructive: Yes

  ROTATE TEST-CA
         , CONFIRM

Action options:

CONFIRM

  Confirms the destructive test CA operation.

Command: VERIFY TEST-CA

VERIFY TEST-CA Command

Verifies the test CA certificate, private key, and stored metadata.

Command attributes:
  Session: Required
  Destructive: No

  VERIFY TEST-CA

Command: ALTER WORK-FILES

ALTER WORK-FILES Command

Changes work-file configuration properties.

Command attributes:
  Session: Required
  Destructive: Yes

  ALTER WORK-FILES
        [ , LOCATION <volume>.<subvol> ]
        [ , RETENTION <seconds> ]
        [ , CLEAN-INTERVAL <seconds> ]

Properties:

LOCATION <volume>.<subvol>

  The Guardian subvolume used for work files.

RETENTION <seconds>

  The completed work-file retention period.

CLEAN-INTERVAL <seconds>

  The interval between work-file cleanups.

Command: CLEAN WORK-FILES

CLEAN WORK-FILES Command

Requests cleanup of eligible ActivCERT work files.

Command attributes:
  Session: Required
  Destructive: Yes

  CLEAN WORK-FILES

Command: INFO WORK-FILES

INFO WORK-FILES Command

Displays the active work-file configuration.

Command attributes:
  Session: Required
  Destructive: No

  INFO WORK-FILES