ActivCERT

Create the datastore and start CERTMON

Datastore location

ActivCERT stores its configuration, protected credentials, certificate versions, and operating history in one Guardian subvolume. You may relocate the datastore, but copy or restore the complete file set together. Guardian names are case-insensitive.

Where a datastore location is accepted, * selects the current TACL subvolume.

Create, validate, and inspect

Start CERTCOM from TACL, create the datastore files, validate their structure, and inspect the resulting datastore before exiting. These commands do not require an open CERTMON session. The example selects the current TACL subvolume with *; confirm that it is the intended new datastore location before creating files:

RUN CERTCOM
CREATE DATASTORE *
VALIDATE DATASTORE *, DETAIL
INFO DATASTORE *, DETAIL
EXIT

CREATE DATASTORE creates the Enscribe files and initial configuration. Add SAMPLE only when following a procedure that requires the published sample configuration.

Start the process pair

The following example starts process $ACMON in CPU 0 with a backup in CPU 1 and writes process logging to ACLOG in the datastore subvolume:

RUN CERTMON / NAME $ACMON, NOWAIT, CPU 0 / --datastore * --backupcpu 1 --log ACLOG

CERTMON loads LICAC from the program subvolume by default. Use --license <Guardian-file> when the approved license is stored under a different Guardian filename:

RUN CERTMON / NAME $ACMON, NOWAIT, CPU 0 / --datastore * --backupcpu 1 --log ACLOG --license $DATA.LICENSES.LICAC

CERTMON uses the process name supplied by TACL for the primary and backup pair. The backup process takes over when the primary fails.

Examples in this guide use $ACMON as the CERTMON process name. Replace $ACMON with your own process name when entering commands.

Open and verify the service

Start CERTCOM from TACL and open the monitor process you started. Inspect the session, monitor, datastore, and scheduler to confirm that you connected to the intended service:

RUN CERTCOM
OPEN $ACMON
STATUS SESSION
STATUS MONITOR, DETAIL
INFO DATASTORE
STATUS SCHEDULER, DETAIL

A healthy process pair reports service state RUNNING, the intended datastore, Backup Configured YES, and Backup Status RUNNING. CERTCOM is an interactive command interface and does not write to the CERTMON process log.

RUN CERTCOM $ACMON is equivalent to starting CERTCOM with RUN CERTCOM and then entering OPEN $ACMON. Use the one-step form when the active monitor process name is already known.

Follow the process name with semicolon-separated commands to run a batch:

RUN CERTCOM $ACMON ; STATUS MONITOR
RUN CERTCOM $ACMON ; STATUS SESSION ; INFO DATASTORE

CERTCOM opens the requested monitor, executes the commands in order, and exits with the batch completion code. A failed OPEN stops the batch before subsequent commands execute. Command-only startup also supports explicit OPEN:

RUN CERTCOM OPEN $ACMON ; STATUS MONITOR

Stop and restart

Allow active tasks to finish before stopping:

STOP MONITOR, DRAIN

Stop without waiting only when active work must not delay shutdown:

STOP MONITOR, NOW

DRAIN is the default. Read-only commands remain available while CERTMON finishes accepted tasks and stops.