ActivCERT

Configure credentials, DNS, and issuers

Before adding a certificate, configure the credentials, DNS provider, and issuer it will use. Credentials store passwords and keys, the DNS provider verifies control of your domain names, and the issuer supplies certificates. Replace the sample names and locations with those for your installation.

Open the service and optionally freeze scheduling

Open the service before changing runtime configuration. Routine configuration changes do not require the scheduler to be frozen.

OPEN $ACMON

Use FREEZE SCHEDULER if you need to pause automatic work during setup or maintenance. Tasks already running continue, and you can still enter commands to start work yourself. To pause scheduling, enter:

FREEZE SCHEDULER, REASON 'Staged initial certificate configuration'

Add protected credentials

Configuration object names are case-insensitive when referenced or selected. For example, a key policy created as RSA-2048 may be referenced as rsa-2048. Names retain their entered spelling for display, and names that differ only by ASCII letter case cannot identify separate objects of the same type. DNS providers share one name namespace; file and LightWave targets share another. Credential contents, URLs, paths and certificate attribute values retain their existing case rules.

CERTCOM refers to protected values by credential name. Use PROMPT for interactive entry or FROM-FILE for a secured Guardian source file. Stored values are never displayed by INFO.

ADD CREDENTIAL p12-passphrase, TYPE PKCS12-PASSPHRASE, PROMPT
INFO CREDENTIAL p12-passphrase

For an existing private key, read its contents from a secured Guardian file into a PRIVATE-KEY credential:

ADD CREDENTIAL imported-key, TYPE PRIVATE-KEY, &
  FROM-FILE $DATA.SECRET.KEYFILE

Credential type

Typical use

ACME-ACCOUNT-KEY

Existing ACME account private key.

EAB-SECRET

ACME external account binding secret.

PKCS12-PASSPHRASE

Passphrase for PKCS12 deployment targets.

PRIVATE-KEY

Imported certificate private key.

GENERAL-SECRET

DNS provider access keys, tokens, user names, and passwords.

Secret handling. Do not place passwords, private keys, tokens, or passphrases directly in CERTCOM commands, command files, support transcripts, or event exports.

Choose the credential type that matches its use. PKCS12 import, export, and deployment require a PKCS12-PASSPHRASE credential. DNS providers and other authentication settings use GENERAL-SECRET credentials. ActivCERT rejects a credential whose type does not match the command.

Optionally configure the built-in TEST-CA issuer

For training or non-production testing, create the built-in certificate authority, verify it, and inspect its details before configuring an issuer that uses it:

CREATE TEST-CA, COMMON-NAME 'ActivCERT Test CA', VALIDITY-DAYS 3650
VERIFY TEST-CA
INFO TEST-CA, DETAIL

Export only the public TEST-CA certificate when a non-production trust store needs it:

EXPORT TEST-CA, FILE $DATA.CERTS.ACTCA

TEST-CA use. The built-in CA supports testing, training, and non-production evaluation. It is not a production trust source.

Create a named issuer that makes the TEST-CA available to managed certificates, then verify and inspect that issuer:

ADD ISSUER test-issuer, TYPE TEST-CA
VERIFY ISSUER test-issuer, WAIT
INFO ISSUER test-issuer, DETAIL

Any number of managed certificates can reference the same TEST-CA issuer.

Configure Amazon Route 53 as a DNS provider example

This example configures a Route 53 DNS provider. Create credentials for the AWS access key identifier, secret access key, and session token. Omit the token credential and SESSION-TOKEN parameter only when your AWS credentials do not require a token. See DNS provider configuration procedures for the other providers.

ADD CREDENTIAL route53-access, TYPE GENERAL-SECRET, PROMPT
ADD CREDENTIAL route53-secret, TYPE GENERAL-SECRET, PROMPT
ADD CREDENTIAL route53-token, TYPE GENERAL-SECRET, PROMPT
ADD DCV-ROUTE53 public-dns, ACCESS-KEY-ID route53-access, &
  SECRET-ACCESS-KEY route53-secret, SESSION-TOKEN route53-token, &
  REGION us-east-1, HOSTED-ZONE-ID <hosted-zone-id>, TTL 60
VERIFY DCV-ROUTE53 public-dns, WAIT
INFO DCV public-dns
INFO DCV-ROUTE53 public-dns, DETAIL

HOSTED-ZONE-ID restricts the provider to a specific Route 53 hosted zone. ENDPOINT supplies a site-approved API endpoint override.

Configure another DNS provider

Follow DNS provider configuration procedures to add an Azure DNS or deSEC provider.

To inspect providers already configured, list the generic DCV collection or select one provider by name. Use the Azure or deSEC detail command that matches its type; these queries do not create a provider:

INFO DCV *
INFO DCV <provider-name>
INFO DCV-AZURE <provider-name>, DETAIL
INFO DCV-DESEC <provider-name>, DETAIL

Each ACME issuer selects a provider with DCV <provider-name>. Provider-specific credentials remain protected and are referenced by name.

Configure an ACME issuer

An ACME issuer specifies the certificate authority, account key, and domain validation method to use. In this example, ActivCERT creates and protects a new account key. See ACME service configuration procedures for examples using specific certificate authorities:

ADD ISSUER public-acme, TYPE ACME, &
  DIRECTORY <acme-directory-url>, GENERATE-ACCOUNT-KEY, &
  DCV public-dns, CONTACT mailto:certificates@example.com, &
  TRUST-ANCHOR CACERT
VERIFY ISSUER public-acme, WAIT
INFO ISSUER public-acme, DETAIL

Option

Use

ACCOUNT-KEY

Use an existing ACME account key stored as an ACME-ACCOUNT-KEY credential.

GENERATE-ACCOUNT-KEY

Generate and protect a new account key during account setup.

DCV

Select EXTERNAL validation or a named DNS provider for ACME authorization.

CONTACT

Supply the ACME account contact, normally a mailto address.

EAB-KEY-ID / EAB-CREDENTIAL

Supply external account binding when required by the ACME service.

TRUST-ANCHOR

Trust a site-provided CA file for the ACME TLS connection.

PROXY

Send ACME HTTPS traffic through the specified proxy.

CONNECT-TIMEOUT / READ-TIMEOUT

Set site-specific ACME connection and response time limits.

Run VERIFY ISSUER after changing the issuer, its credentials, DNS provider, trust anchor, proxy, or network path.

Detailed ACME issuer INFO displays EAB Credential as the configured credential name, NONE when absent, or UNAVAILABLE when its record cannot be resolved. Protected credential values remain redacted.