Use HELP in CERTCOM for command syntax matching your installed version.
Command: Repeat
! Command
Causes a previous command to be executed.
Command attributes:
Session: Not required
Destructive: No
! [ [ - ] <number> | <character-string> ]
Command target:
[ - ] <number> | <character-string>
The command number or the first few characters of the command to be
re-executed.
Command: ALLOW
ALLOW Command
Specifies the maximum number of warnings or errors that are allowed to occur
before execution of an OBEY file or IN file is terminated.
Command attributes:
Session: Not required
Destructive: No
ALLOW [ [ <count> | ALL | NO ] [ ERRORS | WARNINGS ] ]
Command target:
[ <count> | ALL | NO ] [ ERRORS | WARNINGS ]
ALL indicates that there is no limit on the number of errors or warnings. NO
indicates that no errors or warnings are allowed. <count> is an integer
specifying the number or errors or warnings. If the ALLOW command is used
with no parameters, the default setting is NO ERRORS and ALL WARNINGS. If
ERRORS or WARNINGS is specified but ALL, NO, and <count> are omitted, ALL is
assumed. IF ALL, NO, or <count> is specified, but ERRORS and WARNINGS are
omitted, ERRORS is assumed.
Command: CLOSE
CLOSE Command
Closes the active CERTCOM session.
Command attributes:
Session: Required
Destructive: No
CLOSE
Command: ENV
ENV Command
Displays information about the program environment.
Command attributes:
Session: Not required
Destructive: No
ENV
Command: EXIT
EXIT Command
Stops the program.
Command attributes:
Session: Not required
Destructive: No
EXIT
Command: FC
FC Command
Causes a previous command to be executed.
Command attributes:
Session: Not required
Destructive: No
FC [ [ - ] <number> | <string> ]
Command target:
[ - ] <number> | <string>
The command number or the first few characters of the command to fix.
Command: HELP
HELP Command
Displays the syntax for commands.
Command attributes:
Session: Not required
Destructive: No
HELP [ help-spec ]
Command target:
help-spec
The command and/or object for which help should be displayed.
Command: HISTORY
HISTORY Command
Shows the most recent commands.
Command attributes:
Session: Not required
Destructive: No
HISTORY [ <number> ]
Command target:
<number>
The number of commands to be displayed. If omitted, the 10 most recent
commands are displayed.
Command: OBEY
OBEY Command
Causes commands to be read from a command file.
Command attributes:
Session: Not required
Destructive: No
OBEY obey-file
Command target:
obey-file
The command file from which commands are to be read.
Command: OPEN
OPEN Command
Opens a CERTCOM session with an ActivCERT monitor.
Command attributes:
Session: Not required
Destructive: No
OPEN <process-name>
Command target:
<process-name>
The Guardian process name of the ActivCERT monitor.
Command: PAGESIZE
PAGESIZE Command
Sets the size of a display page on the terminal screen.
Command attributes:
Session: Not required
Destructive: No
PAGESIZE [ <integer> ]
Command target:
<integer>
If <integer> in the range 2 - 255, <integer> lines will be displayed before
providing a page break. If omitted or -1, output will be displayed without
page breaks. If omitted, the default value is "-1".
Command: STATUS
STATUS Command
Displays ActivCERT product health.
Reports monitor health, datastore and service state, scheduler state, open
work, expiration risk, recent failures, and recommended operator actions.
Command attributes:
Session: Required
Destructive: No
STATUS
[ , DETAIL ]
Output options:
DETAIL
Displays the last scheduler scan time.
Command: VOLUME
VOLUME Command
Specifies the default subvolume for the expansion of all file names.
Command attributes:
Session: Not required
Destructive: No
VOLUME [ <subvolume-name> ]
Command target:
<subvolume-name>
The name of the subvolume that is to become the default. If omitted, the
program default subvolume is used.
Command: ADD CERTIFICATE
ADD CERTIFICATE Command
Creates a managed certificate.
Configuration object names accept any ASCII letter case when referenced;
stored spelling is preserved and case-only duplicates are rejected. Missing
references identify the failed object type and name. Correct the first
reported reference and retry; use the suggested INFO collection to check
configured names.
Command attributes:
Session: Required
Destructive: Yes
ADD CERTIFICATE <certificate-name>, ISSUER <issuer-name>, RENEWAL-POLICY
<policy-name>, KEY-POLICY <key-policy-name> [ , PRIVATE-KEY
<credential-name> ], SUBJECT <subject> [ , SAN <san-list> ]
Command target:
<certificate-name>
The managed certificate name.
Properties:
ISSUER <issuer-name>
The certificate issuer.
RENEWAL-POLICY <policy-name>
The renewal policy.
KEY-POLICY <key-policy-name>
The certificate key policy.
PRIVATE-KEY <credential-name>
The private key credential required by an imported-key policy.
SUBJECT <subject>
DNS hostname (stored as CN=<hostname>) or comma-separated attribute=value
DN. Attribute names accept any case; values are preserved. Omitted SAN
defaults to a single DNS common name.
SAN <san-list>
The certificate subject alternative names. DNS, IP, URI and email prefixes
accept any case; values are preserved.
Command: ADOPT CERTIFICATE
ADOPT CERTIFICATE Command
Brings an existing certificate installation under management.
Command attributes:
Session: Required
Destructive: Yes
ADOPT CERTIFICATE <certificate-name>, SOURCE FILE, TARGET <target-name>,
ISSUER <issuer-name>, RENEWAL-POLICY <policy-name>, KEY-POLICY
<key-policy-name>, FORMAT PEM-SEPARATE, FILE-TYPE EDIT | STREAM, CERT-FILE
<guardian-file>, KEY-FILE <guardian-file> [ , CHAIN-FILE <guardian-file> ] [
, FULLCHAIN-FILE <guardian-file> ] [ , WAIT ]
ADOPT CERTIFICATE <certificate-name>, SOURCE FILE, TARGET <target-name>,
ISSUER <issuer-name>, RENEWAL-POLICY <policy-name>, KEY-POLICY
<key-policy-name>, FORMAT PEM-FULLCHAIN, FILE-TYPE EDIT | STREAM,
FULLCHAIN-FILE <guardian-file>, KEY-FILE <guardian-file> [ , WAIT ]
ADOPT CERTIFICATE <certificate-name>, SOURCE FILE, TARGET <target-name>,
ISSUER <issuer-name>, RENEWAL-POLICY <policy-name>, KEY-POLICY
<key-policy-name>, FORMAT PKCS12, FILE-TYPE BINARY, PKCS12-FILE
<guardian-file>, PASSPHRASE <credential-name> | NO-PASSPHRASE [ , WAIT ]
ADOPT CERTIFICATE <certificate-name>, SOURCE LIGHTWAVE, TARGET
<target-name>, ISSUER <issuer-name>, RENEWAL-POLICY <policy-name>,
KEY-POLICY <key-policy-name>, PROGRAM-FILE <guardian-file>, CERT-SPEC
<certificate-spec>, PASSPHRASE <credential-name> [ , COMMON-NAME
<common-name> ] [ , IMPORT-CHAIN ON | OFF ] [ , EXPORT-CHAIN ON | OFF ] [ ,
WAIT ]
Command target:
<certificate-name>
The managed certificate name.
Action options:
SOURCE FILE | LIGHTWAVE
The certificate onboarding source.
TARGET <target-name>
The source target name to create.
ISSUER <issuer-name>
The certificate issuer.
RENEWAL-POLICY <policy-name>
The renewal policy.
KEY-POLICY <key-policy-name>
The certificate key policy.
PROGRAM-FILE <guardian-file>
The fully qualified LWSCOM or LWCCOM program file.
CERT-SPEC <certificate-spec>
The LWxCOM certificate specification.
COMMON-NAME <common-name>
Display metadata for the LightWave target.
IMPORT-CHAIN ON | OFF
Controls future chain import through LWxCOM.
EXPORT-CHAIN ON | OFF
Controls source chain export through LWxCOM.
FORMAT PEM-SEPARATE | PEM-FULLCHAIN | PKCS12
The Guardian file source and target format.
FILE-TYPE EDIT | STREAM | BINARY
The Guardian file type.
CERT-FILE <guardian-file>
The separate PEM certificate file.
KEY-FILE <guardian-file>
The PEM private key file.
CHAIN-FILE <guardian-file>
The separate PEM chain file.
FULLCHAIN-FILE <guardian-file>
Full-chain source for PEM-FULLCHAIN; optional deployment output for
PEM-SEPARATE (uses REPLACE-OR-CREATE).
PKCS12-FILE <guardian-file>
The PKCS12 certificate archive.
PASSPHRASE <credential-name>
The PKCS12 passphrase credential.
NO-PASSPHRASE
The PKCS12 archive has an empty passphrase.
WAIT
Waits for submitted work to finish.
Command: ALTER CERTIFICATE
ALTER CERTIFICATE Command
Changes a managed certificate.
Command attributes:
Session: Required
Destructive: Yes
ALTER CERTIFICATE <certificate-name> [ , NAME <new-name> ] [ , ISSUER
<issuer-name> ] [ , RENEWAL-POLICY <policy-name> ] [ , KEY-POLICY
<key-policy-name> ] [ , PRIVATE-KEY <credential-name> ] [ , SUBJECT
<subject> ] [ , SAN <san-list> ] [ , ENABLED ON | OFF ]
ALTER CERTIFICATE <certificate-name>, VERSION <number>, QUARANTINE ON,
REASON <reason>
ALTER CERTIFICATE <certificate-name>, VERSION <number>, QUARANTINE OFF
Command target:
<certificate-name>
The managed certificate name.
Properties:
VERSION <number>
A positive version number within this certificate.
QUARANTINE ON | OFF
Controls deployment quarantine for the selected version.
REASON <text>
Records why the version is quarantined.
NAME <new-name>
The new managed certificate name.
ISSUER <issuer-name>
The certificate issuer.
RENEWAL-POLICY <policy-name>
The renewal policy.
KEY-POLICY <key-policy-name>
The certificate key policy.
PRIVATE-KEY <credential-name>
The private key credential required by an imported-key policy.
SUBJECT <subject>
DNS hostname (stored as CN=<hostname>) or comma-separated attribute=value
DN. Attribute names accept any case; values are preserved. Omitted SAN
defaults to a single DNS common name.
SAN <san-list>
The certificate subject alternative names. DNS, IP, URI and email prefixes
accept any case; values are preserved.
ENABLED ON | OFF
Controls whether the managed certificate may be processed.
Command: DELETE CERTIFICATE
DELETE CERTIFICATE Command
Deletes a disabled, unreferenced managed certificate.
Command attributes:
Session: Required
Destructive: Yes
DELETE CERTIFICATE <certificate-name>
Command target:
<certificate-name>
The managed certificate name.
Command: DEPLOY CERTIFICATE
DEPLOY CERTIFICATE Command
Submits deployment work for a managed certificate.
Command attributes:
Session: Required
Destructive: Yes
DEPLOY CERTIFICATE <certificate-name>
[ , TARGET <target-name> ]
[ , OVERRIDE-WINDOW ]
[ , WAIT ]
Command target:
<certificate-name>
The managed certificate name.
Action options:
TARGET <target-name>
Selects one deployment target.
OVERRIDE-WINDOW
Starts the deployment outside its configured maintenance window.
WAIT
Waits for submitted deployment work.
Command: INFO CERTIFICATE
INFO CERTIFICATE Command
Displays managed certificates and their current version state.
Timestamps use
whole-second UTC display without rounding.
Command attributes:
Session: Required
Destructive: No
INFO CERTIFICATE <certificate-name> [ , DETAIL ]
INFO CERTIFICATE <certificate-name>, LINKS
INFO CERTIFICATE <certificate-name>, VERSIONS [ , DETAIL ]
INFO CERTIFICATE <certificate-name>, VERSION <number> [ , DETAIL ]
INFO CERTIFICATE <certificate-name>, HISTORY [ , RECENT <count> ]
INFO CERTIFICATE * [ , ENABLED | DISABLED ] [ , EXPIRING [ , DAYS <count> ]
]
Command target:
<certificate-name> | *
The certificate name, or * for all certificates.
Selection filters:
VERSION <number>
A positive version number within this certificate.
VERSIONS
Lists stored versions of this certificate.
ENABLED
Selects enabled certificates.
DISABLED
Selects disabled certificates.
EXPIRING
Selects expiring certificates.
DAYS <count>
Overrides the configured certificate expiration window.
Output options:
DETAIL
Displays additional stored version information when VERSION or VERSIONS is
selected.
HISTORY
Displays the managed certificate lifecycle.
LINKS
Displays the certificate and its current related objects.
Command: ISSUE CERTIFICATE
ISSUE CERTIFICATE Command
Submits initial issuance and eligible target deployment work.
DEPLOY-AFTER-RENEW must be ON for the renewal policy and target.
WAIT includes
selected deployment work; deployment windows apply.
Command attributes:
Session: Required
Destructive: Yes
ISSUE CERTIFICATE <certificate-name>
[ , WAIT ]
Command target:
<certificate-name>
The managed certificate name.
Action options:
WAIT
Waits for submitted work to finish.
Command: RENEW CERTIFICATE
RENEW CERTIFICATE Command
Submits certificate renewal work.
Command attributes:
Session: Required
Destructive: Yes
RENEW CERTIFICATE <certificate-name>
[ , FORCE ]
[ , WAIT ]
Command target:
<certificate-name>
The managed certificate name.
Action options:
FORCE
Bypasses renewal due-state checks when allowed.
WAIT
Waits for submitted renewal work.
Command: STATUS CERTIFICATE
STATUS CERTIFICATE Command
Displays dynamic certificate and renewal state.
Command attributes:
Session: Required
Destructive: No
STATUS CERTIFICATE <certificate-name>
[ , DETAIL ]
Command target:
<certificate-name>
The managed certificate name.
Output options:
DETAIL
Displays additional certificate information.
Command: ALTER CONFIGURATION
ALTER CONFIGURATION Command
Changes ActivCERT configuration properties.
Command attributes:
Session: Required
Destructive: Yes
ALTER CONFIGURATION
[ , CERTIFICATE-VERSION-RETENTION <seconds> ]
[ , DIAGNOSTIC-RETENTION <seconds> ]
[ , TASK-RETENTION <seconds> ]
[ , EVENT-RETENTION <seconds> ]
[ , ACME-ORDER-RETENTION <seconds> ]
[ , RUNTIME-STATUS-RETENTION <seconds> ]
[ , SNAPSHOT-RETENTION <seconds> ]
[ , SHUTDOWN-DRAIN-TIMEOUT <seconds> ]
[ , MAXIMUM-ACME-WORKERS <count> ]
[ , MAXIMUM-LIGHTWAVE-WORKERS <count> ]
[ , MAXIMUM-FILE-WORKERS <count> ]
[ , ACME-USER-AGENT <string>|* ]
Properties:
CERTIFICATE-VERSION-RETENTION <seconds>
The certificate-version retention period.
DIAGNOSTIC-RETENTION <seconds>
The diagnostic-artifact retention period.
TASK-RETENTION <seconds>
The completed-task retention period.
EVENT-RETENTION <seconds>
The event retention period.
ACME-ORDER-RETENTION <seconds>
The ACME order retention period.
RUNTIME-STATUS-RETENTION <seconds>
The stopped runtime-status retention period.
SNAPSHOT-RETENTION <seconds>
The completed work snapshot retention period.
SHUTDOWN-DRAIN-TIMEOUT <seconds>
The maximum graceful shutdown drain period.
MAXIMUM-ACME-WORKERS <count>
The maximum number of concurrent ACME workers.
MAXIMUM-LIGHTWAVE-WORKERS <count>
The maximum number of concurrent LightWave workers.
MAXIMUM-FILE-WORKERS <count>
The maximum number of concurrent Guardian file workers.
ACME-USER-AGENT <string>|*
The complete ACME HTTP User-Agent (1-128 printable ASCII characters). Use *
to reset to ActivCERT.
Command: INFO CONFIGURATION
INFO CONFIGURATION Command
Displays the active ActivCERT configuration.
Command attributes:
Session: Required
Destructive: No
INFO CONFIGURATION
[ , DETAIL ]
Output options:
DETAIL
Displays additional configuration information.
Command: ADD CREDENTIAL
ADD CREDENTIAL Command
Creates a protected credential.
Command attributes:
Session: Required
Destructive: Yes
ADD CREDENTIAL <credential-name>, TYPE <credential-type>, ( PROMPT |
FROM-FILE <guardian-file> ) [ , OWNER <entity-type> <entity-name> ]
Command target:
<credential-name>
The credential name.
Properties:
TYPE ACME-ACCOUNT-KEY | EAB-SECRET | PKCS12-PASSPHRASE | PRIVATE-KEY | GENERAL-SECRET
The protected value type; EAB-SECRET accepts CA-provided base64url HMAC
text.
PROMPT
Prompts for the protected value.
FROM-FILE <guardian-file>
Reads the protected value from a file.
OWNER <entity-type> <entity-name>
Associates the credential with an owner.
Command: ALTER CREDENTIAL
ALTER CREDENTIAL Command
Changes credential properties or creates a new protected secret version.
Command attributes:
Session: Required
Destructive: Yes
ALTER CREDENTIAL <credential-name> [ , NAME <new-name> ] [ , PROMPT |
FROM-FILE <guardian-file> ] [ , ENABLED ON | OFF ]
Command target:
<credential-name>
The credential name.
Properties:
NAME <new-name>
The new credential name.
PROMPT
Prompts for the protected value.
FROM-FILE <guardian-file>
Reads the protected value from a file.
ENABLED ON | OFF
Controls whether the credential may be used.
Command: DELETE CREDENTIAL
DELETE CREDENTIAL Command
Deletes an unreferenced credential.
Command attributes:
Session: Required
Destructive: Yes
DELETE CREDENTIAL <credential-name>
Command target:
<credential-name>
The credential name.
Command: INFO CREDENTIAL
INFO CREDENTIAL Command
Displays one or more credentials without protected values.
Command attributes:
Session: Required
Destructive: No
INFO CREDENTIAL <credential-name> [ , DETAIL ]
INFO CREDENTIAL * [ , TYPE <credential-type> ] [ , ENABLED | DISABLED ]
Command target:
<credential-name> | *
The credential name, or * for all credentials.
Selection filters:
TYPE ACME-ACCOUNT-KEY | EAB-SECRET | PKCS12-PASSPHRASE | PRIVATE-KEY | GENERAL-SECRET
The protected value type; EAB-SECRET accepts CA-provided base64url HMAC
text.
ENABLED
Selects enabled credentials.
DISABLED
Selects disabled credentials.
Output options:
DETAIL
Displays credential metadata and diagnostics.
Command: CREATE DATASTORE
CREATE DATASTORE Command
Creates an ActivCERT datastore at an explicit Guardian location.
Command attributes:
Session: Not required
Destructive: Yes
CREATE DATASTORE *|<subvol>|<volume>.<subvol>
Command target:
*|<subvol>|<volume>.<subvol>
The Guardian subvolume where the datastore will be created; * selects the
current subvolume.
Command: DELETE DATASTORE
DELETE DATASTORE Command
Deletes an ActivCERT datastore after confirming its explicit location.
Command attributes:
Session: Not required
Destructive: Yes
DELETE DATASTORE *|<subvol>|<volume>.<subvol>, CONFIRM
*|<subvol>|<volume>.<subvol>
Command target:
*|<subvol>|<volume>.<subvol>
The Guardian subvolume containing the datastore to delete; * selects the
current subvolume.
Action options:
CONFIRM *|<subvol>|<volume>.<subvol>
Repeats the datastore location to confirm deletion; * selects the current
subvolume.
Command: INFO DATASTORE
INFO DATASTORE Command
Displays information about the active or explicitly located ActivCERT
datastore.
Command attributes:
Session: Not required
Destructive: No
INFO DATASTORE [*|<subvol>|<volume>.<subvol>] [, DETAIL]
Command target:
*|<subvol>|<volume>.<subvol>
The datastore location; * selects the current subvolume.
Output options:
DETAIL
Displays additional datastore information.
Command: VALIDATE DATASTORE
VALIDATE DATASTORE Command
Validates an ActivCERT datastore at an explicit Guardian location.
Command attributes:
Session: Not required
Destructive: No
VALIDATE DATASTORE *|<subvol>|<volume>.<subvol>
[ , DETAIL ]
Command target:
*|<subvol>|<volume>.<subvol>
The datastore location; * selects the current subvolume.
Output options:
DETAIL
Displays additional datastore information.
Command: INFO DCV
INFO DCV Command
Displays one or more DCV providers.
Command attributes:
Session: Required
Destructive: No
INFO DCV <provider-name>
INFO DCV *
Command target:
<provider-name> | *
The DCV provider name, or * for all providers.
Output options:
DETAIL
Accepted with the normal provider information.
Command: ADD DCV-AZURE
ADD DCV-AZURE Command
Creates an Azure DNS DCV provider.
Command attributes:
Session: Required
Destructive: Yes
ADD DCV-AZURE <provider-name>, CLIENT-ID <credential-name>, CLIENT-SECRET
<credential-name>, TENANT-ID <tenant-id>, SUBSCRIPTION-ID <subscription-id>,
RESOURCE-GROUP <resource-group>, ZONE <dns-zone> [ , AUTHORITY-ENDPOINT
<url> ] [ , MANAGEMENT-ENDPOINT <url> ] [ , TTL <seconds> ]
Command target:
<provider-name>
The DCV provider name.
Properties:
CLIENT-ID <credential-name>
The credential containing the Entra application client identifier.
CLIENT-SECRET <credential-name>
The credential containing the Entra application client secret.
TENANT-ID <tenant-id>
The Entra tenant identifier.
SUBSCRIPTION-ID <subscription-id>
The Azure subscription identifier.
RESOURCE-GROUP <resource-group>
The Azure resource group name.
ZONE <dns-zone>
The Azure public DNS zone name.
AUTHORITY-ENDPOINT <url>
The optional Entra authority override.
MANAGEMENT-ENDPOINT <url>
The optional Azure API override.
TTL <seconds>
The DNS record lifetime.
Command: ALTER DCV-AZURE
ALTER DCV-AZURE Command
Changes an Azure DNS DCV provider.
Command attributes:
Session: Required
Destructive: Yes
ALTER DCV-AZURE <provider-name>
[ , NAME <new-name> ]
[ , CLIENT-ID <credential-name> ]
[ , CLIENT-SECRET <credential-name> ]
[ , TENANT-ID <tenant-id> ]
[ , SUBSCRIPTION-ID <subscription-id> ]
[ , RESOURCE-GROUP <resource-group> ]
[ , ZONE <dns-zone> ]
[ , AUTHORITY-ENDPOINT <url> ]
[ , MANAGEMENT-ENDPOINT <url> ]
[ , TTL <seconds> ]
[ , ENABLED ON | OFF ]
Command target:
<provider-name>
The DCV provider name.
Properties:
NAME <new-name>
The new DCV provider name.
CLIENT-ID <credential-name>
The credential containing the Entra application client identifier.
CLIENT-SECRET <credential-name>
The credential containing the Entra application client secret.
TENANT-ID <tenant-id>
The Entra tenant identifier.
SUBSCRIPTION-ID <subscription-id>
The Azure subscription identifier.
RESOURCE-GROUP <resource-group>
The Azure resource group name.
ZONE <dns-zone>
The Azure public DNS zone name.
AUTHORITY-ENDPOINT <url>
The optional Entra authority override.
MANAGEMENT-ENDPOINT <url>
The optional Azure API override.
TTL <seconds>
The DNS record lifetime.
ENABLED ON | OFF
Controls whether the provider may be used.
Command: DELETE DCV-AZURE
DELETE DCV-AZURE Command
Deletes an unreferenced Azure DNS DCV provider.
Command attributes:
Session: Required
Destructive: Yes
DELETE DCV-AZURE <provider-name>
Command target:
<provider-name>
The DCV provider name.
Command: INFO DCV-AZURE
INFO DCV-AZURE Command
Displays an Azure DNS DCV provider.
Command attributes:
Session: Required
Destructive: No
INFO DCV-AZURE <provider-name>
[ , DETAIL ]
Command target:
<provider-name>
The DCV provider name.
Output options:
DETAIL
Accepted with the normal provider information.
Command: VERIFY DCV-AZURE
VERIFY DCV-AZURE Command
Submits Azure DNS access and zone verification.
Command attributes:
Session: Required
Destructive: No
VERIFY DCV-AZURE <provider-name>
[ , WAIT ]
Command target:
<provider-name>
The DCV provider name.
Action options:
WAIT
Waits up to five minutes for verification completion. A timeout leaves the
task active; inspect the reported Task Handle with INFO TASK or continue
with WAIT TASK.
Command: ADD DCV-DESEC
ADD DCV-DESEC Command
Creates a deSEC DNS DCV provider.
Command attributes:
Session: Required
Destructive: Yes
ADD DCV-DESEC <provider-name>, API-TOKEN <credential-name>, ZONE <dns-zone>
[ , API-ENDPOINT <url> ] [ , TTL <seconds> ]
Command target:
<provider-name>
The DCV provider name.
Properties:
API-TOKEN <credential-name>
The credential containing the deSEC API token.
ZONE <dns-zone>
The deSEC public DNS zone name.
API-ENDPOINT <url>
The optional deSEC API endpoint override.
TTL <seconds>
The DNS record lifetime.
Command: ALTER DCV-DESEC
ALTER DCV-DESEC Command
Changes a deSEC DNS DCV provider.
Command attributes:
Session: Required
Destructive: Yes
ALTER DCV-DESEC <provider-name>
[ , NAME <new-name> ]
[ , API-TOKEN <credential-name> ]
[ , ZONE <dns-zone> ]
[ , API-ENDPOINT <url> ]
[ , TTL <seconds> ]
[ , ENABLED ON | OFF ]
Command target:
<provider-name>
The DCV provider name.
Properties:
NAME <new-name>
The new DCV provider name.
API-TOKEN <credential-name>
The credential containing the deSEC API token.
ZONE <dns-zone>
The deSEC public DNS zone name.
API-ENDPOINT <url>
The optional deSEC API endpoint override.
TTL <seconds>
The DNS record lifetime.
ENABLED ON | OFF
Controls whether the provider may be used.
Command: DELETE DCV-DESEC
DELETE DCV-DESEC Command
Deletes an unreferenced deSEC DNS DCV provider.
Command attributes:
Session: Required
Destructive: Yes
DELETE DCV-DESEC <provider-name>
Command target:
<provider-name>
The DCV provider name.
Command: INFO DCV-DESEC
INFO DCV-DESEC Command
Displays a deSEC DNS DCV provider.
Command attributes:
Session: Required
Destructive: No
INFO DCV-DESEC <provider-name>
[ , DETAIL ]
Command target:
<provider-name>
The DCV provider name.
Output options:
DETAIL
Accepted with the normal provider information.
Command: VERIFY DCV-DESEC
VERIFY DCV-DESEC Command
Submits deSEC DNS access and zone verification.
Command attributes:
Session: Required
Destructive: No
VERIFY DCV-DESEC <provider-name>
[ , WAIT ]
Command target:
<provider-name>
The DCV provider name.
Action options:
WAIT
Waits up to five minutes for verification completion. A timeout leaves the
task active; inspect the reported Task Handle with INFO TASK or continue
with WAIT TASK.
Command: ADD DCV-ROUTE53
ADD DCV-ROUTE53 Command
Creates a Route 53 DCV provider.
Command attributes:
Session: Required
Destructive: Yes
ADD DCV-ROUTE53 <provider-name>, ACCESS-KEY-ID <credential-name>,
SECRET-ACCESS-KEY <credential-name> [ , SESSION-TOKEN <credential-name> ] [
, REGION <region> ] [ , ENDPOINT <url> ], HOSTED-ZONE-ID <zone-id> [ , TTL
<seconds> ]
Command target:
<provider-name>
The DCV provider name.
Properties:
ACCESS-KEY-ID <credential-name>
The credential containing the AWS access key identifier.
SECRET-ACCESS-KEY <credential-name>
The credential containing the AWS secret access key.
SESSION-TOKEN <credential-name>
The optional credential containing the AWS session token.
REGION <region>
The AWS region.
ENDPOINT <url>
The Route 53 API endpoint override.
HOSTED-ZONE-ID <zone-id>
The Route 53 hosted zone identifier.
TTL <seconds>
The DNS record lifetime.
Command: ALTER DCV-ROUTE53
ALTER DCV-ROUTE53 Command
Changes a Route 53 DCV provider.
Command attributes:
Session: Required
Destructive: Yes
ALTER DCV-ROUTE53 <provider-name> [ , NAME <new-name> ] [ , ACCESS-KEY-ID
<credential-name>, SECRET-ACCESS-KEY <credential-name> ] [ , SESSION-TOKEN
<credential-name> ] [ , REGION <region> ] [ , ENDPOINT <url> ] [ ,
HOSTED-ZONE-ID <zone-id> ] [ , TTL <seconds> ] [ , ENABLED ON | OFF ]
Command target:
<provider-name>
The DCV provider name.
Properties:
NAME <new-name>
The new DCV provider name.
ACCESS-KEY-ID <credential-name>
The credential containing the AWS access key identifier.
SECRET-ACCESS-KEY <credential-name>
The credential containing the AWS secret access key.
SESSION-TOKEN <credential-name>
The optional credential containing the AWS session token.
REGION <region>
The AWS region.
ENDPOINT <url>
The Route 53 API endpoint override.
HOSTED-ZONE-ID <zone-id>
The Route 53 hosted zone identifier.
TTL <seconds>
The DNS record lifetime.
ENABLED ON | OFF
Controls whether the provider may be used.
Command: DELETE DCV-ROUTE53
DELETE DCV-ROUTE53 Command
Deletes an unreferenced Route 53 DCV provider.
Command attributes:
Session: Required
Destructive: Yes
DELETE DCV-ROUTE53 <provider-name>
Command target:
<provider-name>
The DCV provider name.
Command: INFO DCV-ROUTE53
INFO DCV-ROUTE53 Command
Displays one or more Route 53 DCV providers.
Command attributes:
Session: Required
Destructive: No
INFO DCV-ROUTE53 <provider-name> [ , DETAIL ]
INFO DCV-ROUTE53 * [ , ENABLED | DISABLED ]
Command target:
<provider-name> | *
The DCV provider name, or * for all Route 53 providers.
Selection filters:
ENABLED
Selects enabled providers.
DISABLED
Selects disabled providers.
Output options:
DETAIL
Displays provider configuration, transport status, and diagnostics.
Command: VERIFY DCV-ROUTE53
VERIFY DCV-ROUTE53 Command
Submits Route 53 access and hosted-zone verification.
Command attributes:
Session: Required
Destructive: No
VERIFY DCV-ROUTE53 <provider-name>
[ , WAIT ]
Command target:
<provider-name>
The DCV provider name.
Action options:
WAIT
Waits up to five minutes for verification completion. A timeout leaves the
task active; inspect the reported Task Handle with INFO TASK or continue
with WAIT TASK.
Command: INFO DEPLOYMENT
INFO DEPLOYMENT Command
Displays one or more deployment attempts.
Timestamps use whole-second UTC
display without rounding.
Command attributes:
Session: Required
Destructive: No
INFO DEPLOYMENT <deployment-handle> [ , DETAIL ]
INFO DEPLOYMENT * [ , TARGET <target-name> ] [ , CERTIFICATE
<certificate-name> [ , VERSION <number> ] ] [ , TYPE DEPLOY | VERIFY |
ROLLBACK ] [ , STATUS PENDING | RUNNING | VERIFYING | COMPLETED | FAILED |
ABORTED | OPERATOR-ACTION ] [ , RECENT <count> ]
Command target:
<deployment-handle> | *
The deployment attempt handle, or * for all attempts.
Selection filters:
TARGET <target-name>
Selects one deployment target.
CERTIFICATE <certificate-name>
Selects one managed certificate.
VERSION <number>
Selects a version number within the certificate.
TYPE DEPLOY | VERIFY | ROLLBACK
Selects deployment attempts by operation type.
STATUS PENDING | RUNNING | VERIFYING | COMPLETED | FAILED | ABORTED | OPERATOR-ACTION
Selects deployment attempts by status.
Output options:
DETAIL
Displays additional deployment information.
RECENT <count>
Limits output to recent attempts.
Command: ADD DEPLOYMENT-WINDOW
ADD DEPLOYMENT-WINDOW Command
Creates a deployment maintenance window.
Command attributes:
Session: Required
Destructive: Yes
ADD DEPLOYMENT-WINDOW <window-name>
, DAYS <SUN,MON,... | ALL>
, START <HH:MM>
, DURATION-MINUTES <minutes>
Command target:
<window-name>
The deployment window name.
Properties:
DAYS <SUN,MON,... | ALL>
Selected UTC weekdays, supplied as a quoted comma-separated value.
START <HH:MM>
The UTC start time.
DURATION-MINUTES <minutes>
The window duration in minutes.
Command: ALTER DEPLOYMENT-WINDOW
ALTER DEPLOYMENT-WINDOW Command
Changes a deployment maintenance window.
Command attributes:
Session: Required
Destructive: Yes
ALTER DEPLOYMENT-WINDOW <window-name>
[ , NAME <new-name> ]
[ , DAYS <SUN,MON,... | ALL> ]
[ , START <HH:MM> ]
[ , DURATION-MINUTES <minutes> ]
[ , ENABLED ON | OFF ]
Command target:
<window-name>
The deployment window name.
Properties:
NAME <new-name>
The new deployment window name.
DAYS <SUN,MON,... | ALL>
Selected UTC weekdays, supplied as a quoted comma-separated value.
START <HH:MM>
The UTC start time.
DURATION-MINUTES <minutes>
The window duration in minutes.
ENABLED ON | OFF
Controls whether deployments may use the window.
Command: DELETE DEPLOYMENT-WINDOW
DELETE DEPLOYMENT-WINDOW Command
Deletes a disabled, unreferenced deployment window.
Command attributes:
Session: Required
Destructive: Yes
DELETE DEPLOYMENT-WINDOW <window-name>
Command target:
<window-name>
The deployment window name.
Command: INFO DEPLOYMENT-WINDOW
INFO DEPLOYMENT-WINDOW Command
Displays deployment maintenance windows.
Command attributes:
Session: Required
Destructive: No
INFO DEPLOYMENT-WINDOW <window-name> [ , DETAIL ]
INFO DEPLOYMENT-WINDOW * [ , ENABLED | DISABLED ]
Command target:
<window-name> | *
The deployment window name, or * for all windows.
Selection filters:
ENABLED
Selects enabled windows.
DISABLED
Selects disabled windows.
Output options:
DETAIL
Displays deployment window configuration.
Command: EXPORT EVENT
EXPORT EVENT Command
Exports event records as structured data.
The export includes event identifiers, time, severity, component, message,
related object identifiers, and diagnostic reference. CSV is used when FORMAT
is omitted.
Command attributes:
Session: Required
Destructive: Yes
EXPORT EVENT <event-handle>, FILE <guardian-file> [ ! ] [ , FORMAT CSV |
JSON-LINES ]
EXPORT EVENT *, FILE <guardian-file> [ ! ] [ , FORMAT CSV | JSON-LINES ] [ ,
RECENT <count> ] [ , SEVERITY INFO | WARNING | ERROR ]
Command target:
<event-handle> | *
The event handle, or * for all events.
Selection filters:
SEVERITY INFO | WARNING | ERROR
Selects events by severity.
Output options:
FILE <guardian-file> [ ! ]
The Guardian export file.
FORMAT CSV | JSON-LINES
The structured event export format. If omitted, the default value is "CSV".
RECENT <count>
Limits output to recent events.
Command: INFO EVENT
INFO EVENT Command
Displays one or more event records.
An event handle displays complete event information. An asterisk displays a
compact event table.
Command attributes:
Session: Required
Destructive: No
INFO EVENT <event-handle> [ , DETAIL ]
INFO EVENT * [ , RECENT <count> ] [ , SEVERITY INFO | WARNING | ERROR ]
Command target:
<event-handle> | *
The event handle, or * for all events.
Selection filters:
SEVERITY INFO | WARNING | ERROR
Selects events by severity.
Output options:
DETAIL
Accepted with the normal event information.
RECENT <count>
Limits output to recent events.
Command: ADD ISSUER
ADD ISSUER Command
Creates a certificate issuer.
Command attributes:
Session: Required
Destructive: Yes
ADD ISSUER <issuer-name>, TYPE TEST-CA
ADD ISSUER <issuer-name>, TYPE ACME, DIRECTORY <url>, DCV ( EXTERNAL |
<provider-name> ), ( ACCOUNT-KEY <credential-name> | GENERATE-ACCOUNT-KEY )
[ , CONTACT <contact> ] [ , EAB-KEY-ID <key-id> ] [ , EAB-CREDENTIAL
<credential-name> ] [ , TRUST-ANCHOR <guardian-file> ] [ , PROXY <url> ] [ ,
CONNECT-TIMEOUT <seconds> ] [ , READ-TIMEOUT <seconds> ]
Command target:
<issuer-name>
The issuer name.
Properties:
TYPE TEST-CA | ACME
The issuer type.
DIRECTORY <url>
The ACME directory URL.
DCV EXTERNAL | <provider-name>
The external or named DCV provider used for ACME authorization.
ACCOUNT-KEY <credential-name>
The ACME account key credential.
GENERATE-ACCOUNT-KEY
Records intent to generate a protected ACME account key.
CONTACT <contact>
An ACME account contact.
EAB-KEY-ID <key-id>
The external account binding key identifier.
EAB-CREDENTIAL <credential-name>
The EAB-SECRET credential containing the CA-provided base64url HMAC.
TRUST-ANCHOR <guardian-file>
The TLS trust anchor file.
PROXY <url>
The HTTP proxy URL.
CONNECT-TIMEOUT <seconds>
The connection timeout in seconds.
READ-TIMEOUT <seconds>
The read timeout in seconds.
Command: ALTER ISSUER
ALTER ISSUER Command
Changes a certificate issuer.
Command attributes:
Session: Required
Destructive: Yes
ALTER ISSUER <issuer-name>
[ , NAME <new-name> ]
[ , DIRECTORY <url> ]
[ , DCV EXTERNAL | <provider-name> ]
[ , ACCOUNT-KEY <credential-name> ]
[ , GENERATE-ACCOUNT-KEY ]
[ , CONTACT <contact> ]
[ , EAB-KEY-ID <key-id> ]
[ , EAB-CREDENTIAL <credential-name> ]
[ , TRUST-ANCHOR <guardian-file> ]
[ , PROXY <url> ]
[ , CONNECT-TIMEOUT <seconds> ]
[ , READ-TIMEOUT <seconds> ]
[ , ENABLED ON | OFF ]
Command target:
<issuer-name>
The issuer name.
Properties:
NAME <new-name>
The new issuer name.
DIRECTORY <url>
The ACME directory URL.
DCV EXTERNAL | <provider-name>
The external or named DCV provider used for ACME authorization.
ACCOUNT-KEY <credential-name>
The ACME account key credential.
GENERATE-ACCOUNT-KEY
Records intent to generate a protected ACME account key.
CONTACT <contact>
An ACME account contact.
EAB-KEY-ID <key-id>
The external account binding key identifier.
EAB-CREDENTIAL <credential-name>
The EAB-SECRET credential containing the CA-provided base64url HMAC.
TRUST-ANCHOR <guardian-file>
The TLS trust anchor file.
PROXY <url>
The HTTP proxy URL.
CONNECT-TIMEOUT <seconds>
The connection timeout in seconds.
READ-TIMEOUT <seconds>
The read timeout in seconds.
ENABLED ON | OFF
Controls whether the issuer may be used.
Command: DELETE ISSUER
DELETE ISSUER Command
Deletes a disabled, unreferenced certificate issuer.
Command attributes:
Session: Required
Destructive: Yes
DELETE ISSUER <issuer-name>
Command target:
<issuer-name>
The issuer name.
Command: INFO ISSUER
INFO ISSUER Command
Displays one or more certificate issuers.
Command attributes:
Session: Required
Destructive: No
INFO ISSUER <issuer-name> [ , DETAIL ]
INFO ISSUER * [ , TYPE TEST-CA | ACME ] [ , ENABLED | DISABLED ]
Command target:
<issuer-name> | *
The issuer name, or * for all issuers.
Selection filters:
TYPE TEST-CA | ACME
The issuer type.
ENABLED
Selects enabled issuers.
DISABLED
Selects disabled issuers.
Output options:
DETAIL
Displays issuer configuration and diagnostics.
Command: VERIFY ISSUER
VERIFY ISSUER Command
Submits certificate issuer verification work.
Command attributes:
Session: Required
Destructive: No
VERIFY ISSUER <issuer-name>
[ , WAIT ]
Command target:
<issuer-name>
The issuer name.
Action options:
WAIT
Waits for submitted verification work.
Command: ADD KEY-POLICY
ADD KEY-POLICY Command
Creates a certificate key policy.
Command attributes:
Session: Required
Destructive: Yes
ADD KEY-POLICY <policy-name>
, SOURCE GENERATE | IMPORT | REUSE-CURRENT
, ALGORITHM RSA | ECDSA
[ , SIZE <bits> ]
[ , CURVE <curve-name> ]
[ , ROTATE-ON-RENEW ON | OFF ]
[ , PRIVATE-KEY <credential-name> ]
Command target:
<policy-name>
The key policy name.
Properties:
SOURCE GENERATE | IMPORT | REUSE-CURRENT
The private key source.
ALGORITHM RSA | ECDSA
The private key algorithm.
SIZE <bits>
The RSA key size.
CURVE <curve-name>
The ECDSA curve.
ROTATE-ON-RENEW ON | OFF
Controls key rotation for SOURCE GENERATE during renewal.
PRIVATE-KEY <credential-name>
Selects the PRIVATE-KEY credential required by SOURCE IMPORT.
Command: ALTER KEY-POLICY
ALTER KEY-POLICY Command
Changes a certificate key policy.
Command attributes:
Session: Required
Destructive: Yes
ALTER KEY-POLICY <policy-name>
[ , NAME <new-name> ]
[ , SOURCE GENERATE | IMPORT | REUSE-CURRENT ]
[ , ALGORITHM RSA | ECDSA ]
[ , SIZE <bits> ]
[ , CURVE <curve-name> ]
[ , ROTATE-ON-RENEW ON | OFF ]
[ , PRIVATE-KEY <credential-name> ]
[ , ENABLED ON | OFF ]
Command target:
<policy-name>
The key policy name.
Properties:
NAME <new-name>
The new key policy name.
SOURCE GENERATE | IMPORT | REUSE-CURRENT
The private key source.
ALGORITHM RSA | ECDSA
The private key algorithm.
SIZE <bits>
The RSA key size.
CURVE <curve-name>
The ECDSA curve.
ROTATE-ON-RENEW ON | OFF
Controls key rotation for SOURCE GENERATE during renewal.
PRIVATE-KEY <credential-name>
Selects the PRIVATE-KEY credential required by SOURCE IMPORT.
ENABLED ON | OFF
Controls whether the key policy may be used.
Command: DELETE KEY-POLICY
DELETE KEY-POLICY Command
Deletes an unreferenced certificate key policy.
Command attributes:
Session: Required
Destructive: Yes
DELETE KEY-POLICY <policy-name>
Command target:
<policy-name>
The key policy name.
Command: INFO KEY-POLICY
INFO KEY-POLICY Command
Displays one or more certificate key policies.
Command attributes:
Session: Required
Destructive: No
INFO KEY-POLICY <policy-name> [ , DETAIL ]
INFO KEY-POLICY * [ , ENABLED | DISABLED ]
Command target:
<policy-name> | *
The key policy name, or * for all policies.
Selection filters:
ENABLED
Selects enabled key policies.
DISABLED
Selects disabled key policies.
Output options:
DETAIL
Displays key policy configuration.
Command: VALIDATE LICENSE
VALIDATE LICENSE Command
Validates an ActivCERT license before installation.
Command attributes:
Session: Not required
Destructive: No
VALIDATE LICENSE <guardian-file>
Command target:
<guardian-file>
The signed ActivCERT license file to validate.
Command: STATUS MONITOR
STATUS MONITOR Command
Displays the state of the connected ActivCERT monitor.
Command attributes:
Session: Required
Destructive: No
STATUS MONITOR
[ , DETAIL ]
Output options:
DETAIL
Displays additional information.
Command: STOP MONITOR
STOP MONITOR Command
Stops the connected ActivCERT monitor.
Command attributes:
Session: Required
Destructive: Yes
STOP MONITOR [ , DRAIN | NOW ]
Action options:
DRAIN
Allows active work to finish before CERTMON stops.
NOW
Stops CERTMON without waiting for active work.
Command: STATUS PROCESS
STATUS PROCESS Command
Displays ActivCERT process status.
Reports the monitor pair and active worker processes, including Guardian
identity, task ownership, liveness, and configured worker slot consumption.
Command attributes:
Session: Required
Destructive: No
STATUS PROCESS <logical-name> | *
[ , DETAIL ]
Command target:
<logical-name> | *
The Guardian logical process name, or * for all processes.
Output options:
DETAIL
Displays the last scheduler scan time.
Command: CLEAN RECORDS
CLEAN RECORDS Command
Removes expired unreferenced ActivCERT datastore records.
Command attributes:
Session: Required
Destructive: Yes
CLEAN RECORDS
[ , PREVIEW ]
Action options:
PREVIEW
Reports eligible records without removing them.
Command: ADD RENEWAL-POLICY
ADD RENEWAL-POLICY Command
Creates a certificate renewal policy.
Command attributes:
Session: Required
Destructive: Yes
ADD RENEWAL-POLICY <policy-name>
, RENEW-BEFORE <duration>
[ , USE-ARI ON | OFF ]
[ , RETRY-INTERVAL <duration> ]
[ , MAX-RETRIES <count> ]
[ , RANDOM-DELAY <duration> ]
[ , MANUAL-RENEW ON | OFF ]
[ , DEPLOY-AFTER-RENEW ON | OFF ]
Command target:
<policy-name>
The renewal policy name.
Properties:
RENEW-BEFORE <duration>
The renewal window before expiry. Use unsigned seconds or an S, M, H, D
suffix (case-insensitive), for example 10d. Maximum 4294967295 seconds; no
spaces or signs.
USE-ARI ON | OFF
Controls ACME Renewal Information use.
RETRY-INTERVAL <duration>
The delay between renewal retries; default 1h. Use unsigned seconds or an S,
M, H, D suffix (case-insensitive), for example 10d. Maximum 4294967295
seconds; no spaces or signs.
MAX-RETRIES <count>
The maximum renewal retry count.
RANDOM-DELAY <duration>
The scheduler spread applied to renewal; default 15m. Use unsigned seconds
or an S, M, H, D suffix (case-insensitive), for example 10d. Maximum
4294967295 seconds; no spaces or signs.
MANUAL-RENEW ON | OFF
Controls manual renewal permission.
DEPLOY-AFTER-RENEW ON | OFF
Controls deployment after renewal.
Command: ALTER RENEWAL-POLICY
ALTER RENEWAL-POLICY Command
Changes a certificate renewal policy.
Command attributes:
Session: Required
Destructive: Yes
ALTER RENEWAL-POLICY <policy-name>
[ , NAME <new-name> ]
[ , RENEW-BEFORE <duration> ]
[ , USE-ARI ON | OFF ]
[ , RETRY-INTERVAL <duration> ]
[ , MAX-RETRIES <count> ]
[ , RANDOM-DELAY <duration> ]
[ , MANUAL-RENEW ON | OFF ]
[ , DEPLOY-AFTER-RENEW ON | OFF ]
Command target:
<policy-name>
The renewal policy name.
Properties:
NAME <new-name>
The new renewal policy name.
RENEW-BEFORE <duration>
The renewal window before expiry. Use unsigned seconds or an S, M, H, D
suffix (case-insensitive), for example 10d. Maximum 4294967295 seconds; no
spaces or signs.
USE-ARI ON | OFF
Controls ACME Renewal Information use.
RETRY-INTERVAL <duration>
The delay between renewal retries; default 1h. Use unsigned seconds or an S,
M, H, D suffix (case-insensitive), for example 10d. Maximum 4294967295
seconds; no spaces or signs.
MAX-RETRIES <count>
The maximum renewal retry count.
RANDOM-DELAY <duration>
The scheduler spread applied to renewal; default 15m. Use unsigned seconds
or an S, M, H, D suffix (case-insensitive), for example 10d. Maximum
4294967295 seconds; no spaces or signs.
MANUAL-RENEW ON | OFF
Controls manual renewal permission.
DEPLOY-AFTER-RENEW ON | OFF
Controls deployment after renewal.
Command: DELETE RENEWAL-POLICY
DELETE RENEWAL-POLICY Command
Deletes an unreferenced certificate renewal policy.
Command attributes:
Session: Required
Destructive: Yes
DELETE RENEWAL-POLICY <policy-name>
Command target:
<policy-name>
The renewal policy name.
Command: INFO RENEWAL-POLICY
INFO RENEWAL-POLICY Command
Displays one or more certificate renewal policies.
Command attributes:
Session: Required
Destructive: No
INFO RENEWAL-POLICY <policy-name> [ , DETAIL ]
INFO RENEWAL-POLICY *
Command target:
<policy-name> | *
The renewal policy name, or * for all policies.
Output options:
DETAIL
Displays renewal policy configuration.
Command: ALTER SCHEDULER
ALTER SCHEDULER Command
Changes scheduler configuration properties.
Command attributes:
Session: Required
Destructive: Yes
ALTER SCHEDULER
, INTERVAL <seconds>
Properties:
INTERVAL <seconds>
The interval between scheduler runs.
Command: FREEZE SCHEDULER
FREEZE SCHEDULER Command
Stops the scheduler from creating work.
Command attributes:
Session: Required
Destructive: Yes
FREEZE SCHEDULER
[ , REASON <text> ]
Action options:
REASON <text>
Records the scheduler freeze reason.
Command: STATUS SCHEDULER
STATUS SCHEDULER Command
Displays scheduler state and last/next scan times in UTC. Last Scan is the
start time of the last completed scan; NOT RUN precedes the first scan of the
current monitor. Last Scan is UNAVAILABLE without a current monitor runtime
record. Next Scan is NONE while frozen or stopped, or UNAVAILABLE when no
planned time is recorded.
Command attributes:
Session: Required
Destructive: No
STATUS SCHEDULER
[ , DETAIL ]
Output options:
DETAIL
Displays the last scan result and certificate counts.
Command: THAW SCHEDULER
THAW SCHEDULER Command
Allows the scheduler to create work.
Command attributes:
Session: Required
Destructive: Yes
THAW SCHEDULER
Command: STATUS SESSION
STATUS SESSION Command
Displays the state of the CERTCOM session.
Command attributes:
Session: Not required
Destructive: No
STATUS SESSION
Command: DEPLOY TARGET
DEPLOY TARGET Command
Submits deployment work for one target.
Command attributes:
Session: Required
Destructive: Yes
DEPLOY TARGET <target-name>
[ , VERSION <number> ]
[ , OVERRIDE-WINDOW ]
[ , WAIT ]
Command target:
<target-name>
The deployment target name.
Action options:
VERSION <number>
Selects a version number within the certificate.
OVERRIDE-WINDOW
Starts the deployment outside its configured maintenance window.
WAIT
Waits for submitted deployment work.
Command: INFO TARGET
INFO TARGET Command
Displays one or more deployment target configurations.
Command attributes:
Session: Required
Destructive: No
INFO TARGET <target-name> [ , DETAIL ]
INFO TARGET * [ , CERTIFICATE <certificate-name> ] [ , TYPE FILE | LW ] [ ,
ENABLED | DISABLED ]
Command target:
<target-name> | *
The deployment target name, or * for all targets.
Selection filters:
CERTIFICATE <certificate-name>
Selects targets for one managed certificate.
TYPE FILE | LW
Selects targets by deployment type.
ENABLED
Selects enabled entries.
DISABLED
Selects disabled entries.
Output options:
DETAIL
Displays target configuration or state details.
Command: ROLLBACK TARGET
ROLLBACK TARGET Command
Submits target rollback work.
Command attributes:
Session: Required
Destructive: Yes
ROLLBACK TARGET <target-name>
[ , OVERRIDE-WINDOW ]
[ , WAIT ]
Command target:
<target-name>
The deployment target name.
Action options:
OVERRIDE-WINDOW
Starts the deployment outside its configured maintenance window.
WAIT
Waits for submitted deployment work.
Command: STATUS TARGET
STATUS TARGET Command
Displays dynamic deployment target state.
Command attributes:
Session: Required
Destructive: No
STATUS TARGET <target-name> [ , DETAIL ]
STATUS TARGET * [ , CERTIFICATE <certificate-name> ] [ , TYPE FILE | LW ] [
, ENABLED | DISABLED ]
Command target:
<target-name> | *
The deployment target name, or * for all targets.
Selection filters:
CERTIFICATE <certificate-name>
Selects targets for one managed certificate.
TYPE FILE | LW
Selects targets by deployment type.
ENABLED
Selects enabled entries.
DISABLED
Selects disabled entries.
Output options:
DETAIL
Displays target configuration or state details.
Command: VERIFY TARGET
VERIFY TARGET Command
Submits target verification work.
Command attributes:
Session: Required
Destructive: No
VERIFY TARGET <target-name>
[ , OVERRIDE-WINDOW ]
[ , WAIT ]
Command target:
<target-name>
The deployment target name.
Action options:
OVERRIDE-WINDOW
Starts the deployment outside its configured maintenance window.
WAIT
Waits for submitted deployment work.
Command: ADD TARGET-FILE
ADD TARGET-FILE Command
Creates a Guardian file deployment target.
Command attributes:
Session: Required
Destructive: Yes
ADD TARGET-FILE <target-name>, CERTIFICATE <certificate-name>, FORMAT
PEM-SEPARATE, FILE-TYPE <file-type> [ , REPLACE-MODE <replace-mode> ],
CERT-FILE <guardian-file>, KEY-FILE <guardian-file> [ , CHAIN-FILE
<guardian-file> ] [ , FULLCHAIN-FILE <guardian-file> ] ...
ADD TARGET-FILE <target-name>, CERTIFICATE <certificate-name>, FORMAT
PEM-FULLCHAIN, FILE-TYPE <file-type> [ , REPLACE-MODE <replace-mode> ],
FULLCHAIN-FILE <guardian-file>, KEY-FILE <guardian-file> ...
ADD TARGET-FILE <target-name>, CERTIFICATE <certificate-name>, FORMAT
PKCS12, FILE-TYPE <file-type> [ , REPLACE-MODE <replace-mode> ], PKCS12-FILE
<guardian-file>, PASSPHRASE <credential-name> | NO-PASSPHRASE ...
Command target:
<target-name>
The deployment target name.
Properties:
CERTIFICATE <certificate-name>
The managed certificate.
FORMAT PEM-SEPARATE | PEM-FULLCHAIN | PKCS12
The Guardian file target format.
FILE-TYPE EDIT | STREAM | BINARY
The Guardian target file type.
REPLACE-MODE REPLACE-EXISTING | CREATE-ONLY | REPLACE-OR-CREATE
The target file replacement policy. Defaults to REPLACE-OR-CREATE on ADD.
DEPLOY-AFTER-RENEW ON | OFF
Controls deployment after renewal.
VERIFY-AFTER-DEPLOY ON
Verification is required after deployment.
CAPTURE-BASELINE ON | OFF
Controls baseline capture before deployment.
ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF
Allows renewal completion when this target deployment fails.
CERT-FILE <guardian-file>
The separate PEM certificate file.
KEY-FILE <guardian-file>
The separate PEM private key file.
CHAIN-FILE <guardian-file>
The separate PEM chain file.
FULLCHAIN-FILE <guardian-file>
The full-chain PEM file.
PKCS12-FILE <guardian-file>
The PKCS12 output file.
PASSPHRASE <credential-name>
The PKCS12 passphrase credential.
NO-PASSPHRASE
Creates PKCS12 output without a passphrase.
REQUIRE-EXISTING ON | OFF
Controls validation of missing target files.
WINDOW <window-name>
Assigns a deployment maintenance window.
Command: ALTER TARGET-FILE
ALTER TARGET-FILE Command
Changes a Guardian file deployment target.
Command attributes:
Session: Required
Destructive: Yes
ALTER TARGET-FILE <target-name>
[ , NAME <new-name> ]
[ , CERTIFICATE <certificate-name> ]
[ , FORMAT PEM-SEPARATE | PEM-FULLCHAIN | PKCS12 ]
[ , FILE-TYPE EDIT | STREAM | BINARY ]
[ , REPLACE-MODE REPLACE-EXISTING | CREATE-ONLY | REPLACE-OR-CREATE ]
[ , DEPLOY-AFTER-RENEW ON | OFF ]
[ , VERIFY-AFTER-DEPLOY ON ]
[ , CAPTURE-BASELINE ON | OFF ]
[ , ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF ]
[ , CERT-FILE <guardian-file> ]
[ , KEY-FILE <guardian-file> ]
[ , CHAIN-FILE <guardian-file> ]
[ , FULLCHAIN-FILE <guardian-file> ]
[ , PKCS12-FILE <guardian-file> ]
[ , PASSPHRASE <credential-name> ]
[ , NO-PASSPHRASE ]
[ , REQUIRE-EXISTING ON | OFF ]
[ , ENABLED ON | OFF ]
[ , WINDOW <window-name> ]
[ , NO-WINDOW ]
Command target:
<target-name>
The deployment target name.
Properties:
NAME <new-name>
The new deployment target name.
CERTIFICATE <certificate-name>
The managed certificate.
FORMAT PEM-SEPARATE | PEM-FULLCHAIN | PKCS12
The Guardian file target format.
FILE-TYPE EDIT | STREAM | BINARY
The Guardian target file type.
REPLACE-MODE REPLACE-EXISTING | CREATE-ONLY | REPLACE-OR-CREATE
The target file replacement policy. Defaults to REPLACE-OR-CREATE on ADD.
DEPLOY-AFTER-RENEW ON | OFF
Controls deployment after renewal.
VERIFY-AFTER-DEPLOY ON
Verification is required after deployment.
CAPTURE-BASELINE ON | OFF
Controls baseline capture before deployment.
ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF
Allows renewal completion when this target deployment fails.
CERT-FILE <guardian-file>
The separate PEM certificate file.
KEY-FILE <guardian-file>
The separate PEM private key file.
CHAIN-FILE <guardian-file>
The separate PEM chain file.
FULLCHAIN-FILE <guardian-file>
The full-chain PEM file.
PKCS12-FILE <guardian-file>
The PKCS12 output file.
PASSPHRASE <credential-name>
The PKCS12 passphrase credential.
NO-PASSPHRASE
Creates PKCS12 output without a passphrase.
REQUIRE-EXISTING ON | OFF
Controls validation of missing target files.
ENABLED ON | OFF
Controls whether the target may be used.
WINDOW <window-name>
Assigns a deployment maintenance window.
NO-WINDOW
Removes the deployment maintenance window.
Command: DELETE TARGET-FILE
DELETE TARGET-FILE Command
Deletes an unreferenced Guardian file deployment target.
Command attributes:
Session: Required
Destructive: Yes
DELETE TARGET-FILE <target-name>
Command target:
<target-name>
The deployment target name.
Command: INFO TARGET-FILE
INFO TARGET-FILE Command
Displays one or more Guardian file deployment targets.
Command attributes:
Session: Required
Destructive: No
INFO TARGET-FILE <target-name> [ , DETAIL ]
INFO TARGET-FILE * [ , CERTIFICATE <certificate-name> ] [ , ENABLED |
DISABLED ]
Command target:
<target-name> | *
The deployment target name, or * for all targets.
Selection filters:
CERTIFICATE <certificate-name>
Selects targets for one managed certificate.
ENABLED
Selects enabled entries.
DISABLED
Selects disabled entries.
Output options:
DETAIL
Displays target configuration or state details.
Command: ADD TARGET-LW
ADD TARGET-LW Command
Creates a LightWave command deployment target.
Command attributes:
Session: Required
Destructive: Yes
ADD TARGET-LW <target-name>
, CERTIFICATE <certificate-name>
, CERT-SPEC <certificate-spec>
, PROGRAM-FILE <guardian-file>
, PASSPHRASE <credential-name>
[ , COMMON-NAME <common-name> ]
[ , IMPORT-CHAIN ON | OFF ]
[ , EXPORT-CHAIN ON | OFF ]
[ , DEPLOY-AFTER-RENEW ON | OFF ]
[ , VERIFY-AFTER-DEPLOY ON ]
[ , CAPTURE-BASELINE ON | OFF ]
[ , ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF ]
[ , WINDOW <window-name> ]
Command target:
<target-name>
The deployment target name.
Properties:
CERTIFICATE <certificate-name>
The managed certificate.
CERT-SPEC <certificate-spec>
The LWxCOM certificate specification.
PROGRAM-FILE <guardian-file>
The fully qualified LWSCOM or LWCCOM program file.
PASSPHRASE <credential-name>
The PKCS12 passphrase credential.
COMMON-NAME <common-name>
Display metadata for the target.
IMPORT-CHAIN ON | OFF
Controls chain import through LWxCOM.
EXPORT-CHAIN ON | OFF
Controls chain export through LWxCOM.
DEPLOY-AFTER-RENEW ON | OFF
Controls deployment after renewal.
VERIFY-AFTER-DEPLOY ON
Verification is required after deployment.
CAPTURE-BASELINE ON | OFF
Controls baseline capture before deployment.
ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF
Allows renewal completion when this target deployment fails.
WINDOW <window-name>
Assigns a deployment maintenance window.
Command: ALTER TARGET-LW
ALTER TARGET-LW Command
Changes a LightWave deployment target.
Command attributes:
Session: Required
Destructive: Yes
ALTER TARGET-LW <target-name>
[ , NAME <new-name> ]
[ , CERTIFICATE <certificate-name> ]
[ , CERT-SPEC <certificate-spec> ]
[ , PROGRAM-FILE <guardian-file> ]
[ , PASSPHRASE <credential-name> ]
[ , COMMON-NAME <common-name> ]
[ , IMPORT-CHAIN ON | OFF ]
[ , EXPORT-CHAIN ON | OFF ]
[ , DEPLOY-AFTER-RENEW ON | OFF ]
[ , VERIFY-AFTER-DEPLOY ON ]
[ , CAPTURE-BASELINE ON | OFF ]
[ , ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF ]
[ , ENABLED ON | OFF ]
[ , WINDOW <window-name> ]
[ , NO-WINDOW ]
Command target:
<target-name>
The deployment target name.
Properties:
NAME <new-name>
The new deployment target name.
CERTIFICATE <certificate-name>
The managed certificate.
CERT-SPEC <certificate-spec>
The LWxCOM certificate specification.
PROGRAM-FILE <guardian-file>
The fully qualified LWSCOM or LWCCOM program file.
PASSPHRASE <credential-name>
The PKCS12 passphrase credential.
COMMON-NAME <common-name>
Display metadata for the target.
IMPORT-CHAIN ON | OFF
Controls chain import through LWxCOM.
EXPORT-CHAIN ON | OFF
Controls chain export through LWxCOM.
DEPLOY-AFTER-RENEW ON | OFF
Controls deployment after renewal.
VERIFY-AFTER-DEPLOY ON
Verification is required after deployment.
CAPTURE-BASELINE ON | OFF
Controls baseline capture before deployment.
ALLOW-PARTIAL-DEPLOY-SUCCESS ON | OFF
Allows renewal completion when this target deployment fails.
ENABLED ON | OFF
Controls whether the target may be used.
WINDOW <window-name>
Assigns a deployment maintenance window.
NO-WINDOW
Removes the deployment maintenance window.
Command: DELETE TARGET-LW
DELETE TARGET-LW Command
Deletes an unreferenced LightWave deployment target.
Command attributes:
Session: Required
Destructive: Yes
DELETE TARGET-LW <target-name>
Command target:
<target-name>
The deployment target name.
Command: INFO TARGET-LW
INFO TARGET-LW Command
Displays one or more LightWave deployment targets.
Command attributes:
Session: Required
Destructive: No
INFO TARGET-LW <target-name> [ , DETAIL ]
INFO TARGET-LW * [ , CERTIFICATE <certificate-name> ] [ , ENABLED | DISABLED
]
Command target:
<target-name> | *
The deployment target name, or * for all targets.
Selection filters:
CERTIFICATE <certificate-name>
Selects targets for one managed certificate.
ENABLED
Selects enabled entries.
DISABLED
Selects disabled entries.
Output options:
DETAIL
Displays target configuration or state details.
Command: ABORT TASK
ABORT TASK Command
Aborts one task or all open product tasks.
An asterisk aborts pending tasks, requests cancellation for claimed or running
tasks, and makes failed tasks unavailable for retry.
Command attributes:
Session: Required
Destructive: Yes
ABORT TASK <task-handle>
ABORT TASK *
Command target:
<task-handle> | *
The task handle, or * for all open tasks.
Command: INFO TASK
INFO TASK Command
Displays a task and related records.
A task handle displays complete task information. An asterisk displays a
compact task table.
Command attributes:
Session: Required
Destructive: No
INFO TASK <task-handle> [ , DETAIL ]
INFO TASK * [ , ACTIVE | PENDING | RUNNING | COMPLETED | ABORTED | FAILED |
OPERATOR-ACTION | OPEN | RETRY-CLOSED ] [ , RECENT <count> ]
Command target:
<task-handle> | *
The task handle, or * for all tasks.
Selection filters:
ACTIVE
Selects pending, claimed, and running tasks.
PENDING
Selects pending tasks.
RUNNING
Selects running tasks.
COMPLETED
Selects completed tasks.
ABORTED
Selects aborted tasks.
FAILED
Selects failed tasks.
OPERATOR-ACTION
Selects tasks requiring operator action.
OPEN
Selects open tasks.
RETRY-CLOSED
Selects terminal tasks that are no longer available for retry.
Output options:
DETAIL
Accepted with the normal task information.
RECENT <count>
Limits output to recent tasks.
Command: RETRY TASK
RETRY TASK Command
Submits a legal retry for a task.
Command attributes:
Session: Required
Destructive: Yes
RETRY TASK <task-handle>
Command target:
<task-handle>
The task handle.
Command: STATUS TASK
STATUS TASK Command
Displays the current operational state of a task.
Reports the task type, current status, worker, timing, result, and pending
operator action.
Command attributes:
Session: Required
Destructive: No
STATUS TASK <task-handle>
Command target:
<task-handle>
The task handle.
Command: WAIT TASK
WAIT TASK Command
Waits for a task to reach a final state.
Command attributes:
Session: Required
Destructive: No
WAIT TASK <task-handle>
[ , TIMEOUT <seconds> ]
Command target:
<task-handle>
The task handle.
Action options:
TIMEOUT <seconds>
Limits how long CERTCOM waits for completion. If omitted, the default value
is "300".
Command: CREATE TEST-CA
CREATE TEST-CA Command
Creates the built-in non-production certificate authority.
Command attributes:
Session: Required
Destructive: Yes
CREATE TEST-CA
, COMMON-NAME <text>
, VALIDITY-DAYS <days>
Properties:
COMMON-NAME <text>
The test CA common name.
VALIDITY-DAYS <days>
The test CA validity in days.
Command: DELETE TEST-CA
DELETE TEST-CA Command
Deletes the test CA when no configured resources depend on it.
Command attributes:
Session: Required
Destructive: Yes
DELETE TEST-CA
, CONFIRM
Action options:
CONFIRM
Confirms the destructive test CA operation.
Command: EXPORT TEST-CA
EXPORT TEST-CA Command
Exports the public test CA certificate.
Command attributes:
Session: Required
Destructive: Yes
EXPORT TEST-CA, FILE <guardian-file> [ ! ]
Output options:
FILE <guardian-file> [ ! ]
The Guardian export file.
Command: INFO TEST-CA
INFO TEST-CA Command
Displays the built-in non-production certificate authority.
Command attributes:
Session: Required
Destructive: No
INFO TEST-CA
[ , DETAIL ]
Output options:
DETAIL
Displays CA identity and certificate details.
Command: ROTATE TEST-CA
ROTATE TEST-CA Command
Creates a new test CA key and certificate.
Command attributes:
Session: Required
Destructive: Yes
ROTATE TEST-CA
, CONFIRM
Action options:
CONFIRM
Confirms the destructive test CA operation.
Command: VERIFY TEST-CA
VERIFY TEST-CA Command
Verifies the test CA certificate, private key, and stored metadata.
Command attributes:
Session: Required
Destructive: No
VERIFY TEST-CA
Command: ALTER WORK-FILES
ALTER WORK-FILES Command
Changes work-file configuration properties.
Command attributes:
Session: Required
Destructive: Yes
ALTER WORK-FILES
[ , LOCATION <volume>.<subvol> ]
[ , RETENTION <seconds> ]
[ , CLEAN-INTERVAL <seconds> ]
Properties:
LOCATION <volume>.<subvol>
The Guardian subvolume used for work files.
RETENTION <seconds>
The completed work-file retention period.
CLEAN-INTERVAL <seconds>
The interval between work-file cleanups.
Command: CLEAN WORK-FILES
CLEAN WORK-FILES Command
Requests cleanup of eligible ActivCERT work files.
Command attributes:
Session: Required
Destructive: Yes
CLEAN WORK-FILES
Command: INFO WORK-FILES
INFO WORK-FILES Command
Displays the active work-file configuration.
Command attributes:
Session: Required
Destructive: No
INFO WORK-FILES