The following recommendations will help you configure and maintain ActivCERT. Choose settings that meet your application's needs and your site's security and operating procedures.
Security
-
Protect programs, datastore files, work files, and deployed keys with appropriate Guardian ownership and security. Datastore backups also contain sensitive certificate and credential data.
-
Use the credential procedures to enter secrets. Include credential names only in commands, logs, and information sent to support.
-
Give DNS credentials only the permissions needed to manage the selected zones.
-
Check TLS trust and network access to the certificate authority and DNS service.
-
Use a PKCS12-PASSPHRASE credential when required by the archive or LightWave configuration.
-
Use TEST-CA certificates only for training and non-production testing.
Availability and maintenance
-
Run the CERTMON backup on a different CPU from the primary and check that it is running.
-
After starting or restarting CERTMON, check that you are connected to the correct monitor and datastore.
-
Freeze the scheduler when maintenance requires a pause in automatic work. Commands can still start work while the scheduler is frozen.
-
Allow active tasks to finish before stopping the service when possible.
-
Back up all datastore files together, with no transactions in progress. Freezing the scheduler does not stop active tasks or prevent commands from starting new work. Follow Recover, back up, and restore.
-
Check update compatibility before replacing the programs.
Renewal and workload
-
Set RENEW-BEFORE early enough to allow for validation, service outages, and investigation before a certificate expires.
-
Review ARI support, retry limits, random delay, and MANUAL-RENEW for your certificate authority and operating procedures. See Configure certificates and policies for the supported settings.
-
Check worker limits and open tasks before increasing capacity. More concurrent work also means more requests to external services.
-
Keep records long enough to investigate problems and recover from them.
Deployment
-
Check Guardian filenames and replacement settings before deploying a certificate for the first time.
-
For LightWave, check the program location, certificate specification, and credential type.
-
Verify each deployment and check that the application can use the certificate.
-
For automatic deployment, check both the renewal policy and target settings.
-
Use deployment windows to schedule changes. Window times are UTC.
-
Inspect a certificate version before deploying or quarantining it. Select the version by certificate name and version number. Quarantine requires a reason when enabled.
-
Keep a usable version for rollback. Rolling back a target does not change the certificate's current version. See Manage certificates and versions and Deploy to Guardian files.
Monitoring
-
Perform the daily health check.
-
Investigate failed tasks and unexplained warnings or errors before retrying.
-
Check task and event history alongside process logs. Look up message numbers in the Event Message Reference or Command Diagnostic Reference.
-
Keep credentials and sensitive information out of custom ACME User-Agent values.