Before adding a certificate, configure the credentials, DNS provider, and issuer it will use. Credentials store passwords and keys, the DNS provider verifies control of your domain names, and the issuer supplies certificates. Replace the sample names and locations with those for your installation.
Open the service and optionally freeze scheduling
Open the service before changing runtime configuration. Routine configuration changes do not require the scheduler to be frozen.
OPEN $ACMON
Use FREEZE SCHEDULER if you need to pause automatic work during setup or maintenance. Tasks already running continue, and you can still enter commands to start work yourself. To pause scheduling, enter:
FREEZE SCHEDULER, REASON 'Staged initial certificate configuration'
Add protected credentials
Configuration object names are case-insensitive when referenced or selected. For example, a key policy created as RSA-2048 may be referenced as rsa-2048. Names retain their entered spelling for display, and names that differ only by ASCII letter case cannot identify separate objects of the same type. DNS providers share one name namespace; file and LightWave targets share another. Credential contents, URLs, paths and certificate attribute values retain their existing case rules.
CERTCOM refers to protected values by credential name. Use PROMPT for interactive entry or FROM-FILE for a secured Guardian source file. Stored values are never displayed by INFO.
ADD CREDENTIAL p12-passphrase, TYPE PKCS12-PASSPHRASE, PROMPT
INFO CREDENTIAL p12-passphrase
For an existing private key, read its contents from a secured Guardian file into a PRIVATE-KEY credential:
ADD CREDENTIAL imported-key, TYPE PRIVATE-KEY, &
FROM-FILE $DATA.SECRET.KEYFILE
|
Credential type |
Typical use |
|---|---|
|
ACME-ACCOUNT-KEY |
Existing ACME account private key. |
|
EAB-SECRET |
ACME external account binding secret. |
|
PKCS12-PASSPHRASE |
Passphrase for PKCS12 deployment targets. |
|
PRIVATE-KEY |
Imported certificate private key. |
|
GENERAL-SECRET |
DNS provider access keys, tokens, user names, and passwords. |
Secret handling. Do not place passwords, private keys, tokens, or passphrases directly in CERTCOM commands, command files, support transcripts, or event exports.
Choose the credential type that matches its use. PKCS12 import, export, and deployment require a PKCS12-PASSPHRASE credential. DNS providers and other authentication settings use GENERAL-SECRET credentials. ActivCERT rejects a credential whose type does not match the command.
Optionally configure the built-in TEST-CA issuer
For training or non-production testing, create the built-in certificate authority, verify it, and inspect its details before configuring an issuer that uses it:
CREATE TEST-CA, COMMON-NAME 'ActivCERT Test CA', VALIDITY-DAYS 3650
VERIFY TEST-CA
INFO TEST-CA, DETAIL
Export only the public TEST-CA certificate when a non-production trust store needs it:
EXPORT TEST-CA, FILE $DATA.CERTS.ACTCA
TEST-CA use. The built-in CA supports testing, training, and non-production evaluation. It is not a production trust source.
Create a named issuer that makes the TEST-CA available to managed certificates, then verify and inspect that issuer:
ADD ISSUER test-issuer, TYPE TEST-CA
VERIFY ISSUER test-issuer, WAIT
INFO ISSUER test-issuer, DETAIL
Any number of managed certificates can reference the same TEST-CA issuer.
Configure Amazon Route 53 as a DNS provider example
This example configures a Route 53 DNS provider. Create credentials for the AWS access key identifier, secret access key, and session token. Omit the token credential and SESSION-TOKEN parameter only when your AWS credentials do not require a token. See DNS provider configuration procedures for the other providers.
ADD CREDENTIAL route53-access, TYPE GENERAL-SECRET, PROMPT
ADD CREDENTIAL route53-secret, TYPE GENERAL-SECRET, PROMPT
ADD CREDENTIAL route53-token, TYPE GENERAL-SECRET, PROMPT
ADD DCV-ROUTE53 public-dns, ACCESS-KEY-ID route53-access, &
SECRET-ACCESS-KEY route53-secret, SESSION-TOKEN route53-token, &
REGION us-east-1, HOSTED-ZONE-ID <hosted-zone-id>, TTL 60
VERIFY DCV-ROUTE53 public-dns, WAIT
INFO DCV public-dns
INFO DCV-ROUTE53 public-dns, DETAIL
HOSTED-ZONE-ID restricts the provider to a specific Route 53 hosted zone. ENDPOINT supplies a site-approved API endpoint override.
Configure another DNS provider
Follow DNS provider configuration procedures to add an Azure DNS or deSEC provider.
To inspect providers already configured, list the generic DCV collection or select one provider by name. Use the Azure or deSEC detail command that matches its type; these queries do not create a provider:
INFO DCV *
INFO DCV <provider-name>
INFO DCV-AZURE <provider-name>, DETAIL
INFO DCV-DESEC <provider-name>, DETAIL
Each ACME issuer selects a provider with DCV <provider-name>. Provider-specific credentials remain protected and are referenced by name.
Configure an ACME issuer
An ACME issuer specifies the certificate authority, account key, and domain validation method to use. In this example, ActivCERT creates and protects a new account key. See ACME service configuration procedures for examples using specific certificate authorities:
ADD ISSUER public-acme, TYPE ACME, &
DIRECTORY <acme-directory-url>, GENERATE-ACCOUNT-KEY, &
DCV public-dns, CONTACT mailto:certificates@example.com, &
TRUST-ANCHOR CACERT
VERIFY ISSUER public-acme, WAIT
INFO ISSUER public-acme, DETAIL
|
Option |
Use |
|---|---|
|
ACCOUNT-KEY |
Use an existing ACME account key stored as an ACME-ACCOUNT-KEY credential. |
|
GENERATE-ACCOUNT-KEY |
Generate and protect a new account key during account setup. |
|
DCV |
Select EXTERNAL validation or a named DNS provider for ACME authorization. |
|
CONTACT |
Supply the ACME account contact, normally a mailto address. |
|
EAB-KEY-ID / EAB-CREDENTIAL |
Supply external account binding when required by the ACME service. |
|
TRUST-ANCHOR |
Trust a site-provided CA file for the ACME TLS connection. |
|
PROXY |
Send ACME HTTPS traffic through the specified proxy. |
|
CONNECT-TIMEOUT / READ-TIMEOUT |
Set site-specific ACME connection and response time limits. |
Run VERIFY ISSUER after changing the issuer, its credentials, DNS provider, trust anchor, proxy, or network path.
Detailed ACME issuer INFO displays EAB Credential as the configured credential name, NONE when absent, or UNAVAILABLE when its record cannot be resolved. Protected credential values remain redacted.