ActivCERT

Deploy to Guardian files

A Guardian file target specifies where ActivCERT installs a certificate and its private key. Configure the certificate first, then open your service in CERTCOM and add the target. Replace the sample names and filenames with those for your application. Adding a target saves its settings; DEPLOY installs the files.

Supported formats

Format

Files

PEM-FULLCHAIN

Full certificate chain and private key.

PEM-SEPARATE

Leaf certificate, private key, optional chain, and optional full chain.

PKCS12

Binary PKCS12 file protected by a named credential, or explicitly created without a passphrase.

Add a PEM full-chain target

Choose PEM-FULLCHAIN when the application needs the leaf certificate and chain together, with the private key in a separate file. This example configures EDIT files and permits replacement or creation, then displays the saved target:

ADD TARGET-FILE web-files, CERTIFICATE web-server, FORMAT PEM-FULLCHAIN, FILE-TYPE EDIT, REPLACE-MODE REPLACE-OR-CREATE, FULLCHAIN-FILE $DATA.CERTS.WEBFULL, KEY-FILE $DATA.CERTS.WEBKEY
INFO TARGET-FILE web-files, DETAIL

PEM certificate output includes a human-readable CN comment immediately above each BEGIN CERTIFICATE line.

Add separate PEM files

Choose PEM-SEPARATE when the application needs separate certificate, key, and chain files. This example also configures a full-chain output and uses STREAM files with replacement or creation allowed:

ADD TARGET-FILE web-pem, CERTIFICATE web-server, FORMAT PEM-SEPARATE, FILE-TYPE STREAM, REPLACE-MODE REPLACE-OR-CREATE, CERT-FILE $DATA.CERTS.WEBCERT, KEY-FILE $DATA.CERTS.WEBKEY2, CHAIN-FILE $DATA.CERTS.WEBCHAIN, FULLCHAIN-FILE $DATA.CERTS.WEBFULL2

Add a PKCS12 target

Choose PKCS12 when the application consumes a binary certificate archive. Configure its destination and the existing protected passphrase credential; this example permits replacement or creation of the archive:

ADD TARGET-FILE web-p12, CERTIFICATE web-server, FORMAT PKCS12, FILE-TYPE BINARY, REPLACE-MODE REPLACE-OR-CREATE, PKCS12-FILE $DATA.CERTS.WEBP12, PASSPHRASE p12-passphrase

PASSPHRASE names the protected credential; it is not a clear-text passphrase.

Replacement modes and detailed configuration

ADD TARGET-FILE defaults REPLACE-MODE to REPLACE-OR-CREATE when it is omitted. ALTER preserves the existing mode when omitted. Select the mode that matches the installation procedure:

Mode

Behavior

REPLACE-OR-CREATE

Replace an existing destination or create a missing one.

REPLACE-EXISTING

Require each configured destination to exist before replacement.

CREATE-ONLY

Create destinations only when they do not already exist.

REQUIRE-EXISTING ON independently requires configured destinations to exist, including when REPLACE-MODE is REPLACE-OR-CREATE. Inspect both controls before deploying to missing files.

INFO TARGET-FILE web-files, DETAIL

The Configuration group shows the format and file type, format-specific filenames, replacement mode, Require Existing, Deploy After Renew, Verify After Deploy, Capture Baseline, Allow Partial Success, enabled status, and deployment window. PEM-SEPARATE shows Cert File, Key File, Chain File, and Fullchain File; NONE means an optional output is absent. PEM-FULLCHAIN shows Fullchain File and Key File. PKCS12 shows PKCS12 File and safe passphrase credential metadata; NONE identifies an archive configured without a passphrase. Credential values are never displayed.

The Deployment group shows recorded deployment state and version history. Configuration shows the target's settings; deployment state shows what has happened. Compact INFO and wildcard collection output retain the Primary File summary. Use STATUS TARGET to check the target's current status.

Deploy, verify, and roll back

Deploy the certificate's current version to the configured target, wait for completion, and verify the installed result. Inspect target status and recent deployment records to review the outcome before accepting it for application use:

DEPLOY TARGET web-files, WAIT
VERIFY TARGET web-files, WAIT
STATUS TARGET web-files, DETAIL
INFO DEPLOYMENT *, TARGET web-files, RECENT 10

STATUS TARGET shows the certificate name and its deployed, desired, observed, and rollback version numbers. DEPLOY TARGET <target-name>, VERSION <number> selects a retained version of the target's certificate. Omitting VERSION uses the current version. INFO DEPLOYMENT *, CERTIFICATE <certificate-name>, VERSION <number> filters deployment history by a certificate and its version; VERSION requires CERTIFICATE for this filter.

Restore the previous successful target version without changing the active certificate version:

ROLLBACK TARGET web-files, WAIT
VERIFY TARGET web-files, WAIT
STATUS TARGET web-files, DETAIL

Deploy the active certificate version again to restore the target:

DEPLOY TARGET web-files, WAIT
VERIFY TARGET web-files, WAIT

Guardian file controls. The operator chooses Guardian ownership, security, file type, and replacement behavior appropriate for the consuming application. ActivCERT reports file-operation failures but does not enforce a site security policy.