Prepare for installation
-
Select an empty Guardian subvolume for the ActivCERT programs.
-
Obtain the signed ActivCERT license file supplied for the licensed Guardian system. The license is delivered separately from the customer package.
-
Select a Guardian subvolume for the ActivCERT datastore. The datastore must be created on a TMF audited volume.
-
Choose a unique Guardian process name and primary and backup CPUs for CERTMON.
-
Confirm network access to each ACME directory and DNS provider endpoint that the installation will use.
-
Identify the Guardian ownership and security settings required by site policy.
Install and verify ActivCERT
Replace the placeholders with the package file, signed license file, and Guardian locations supplied for your installation. Install the complete package into one empty program subvolume. Keep all installed programs and CACERT from the same package; do not combine files from different ActivCERT packages. LICAC is supplied and installed separately.
VOLUME <install-subvolume>
UNPAK <release-subvolume>.<package-file>, *, MYID, LISTALL
FUP DUP <license-file>, <install-subvolume>.LICAC, PURGE
RUN <install-subvolume>.CERTCOM VALIDATE LICENSE <install-subvolume>.LICAC
VPROC CERTCOM
VPROC CERTMON
Confirm that VPROC identifies the expected ActivCERT version. Continue only when VALIDATE LICENSE completes successfully and reports SUCCESS: ActivCERT license is valid.
Verify the installed files
The ActivCERT customer package contains the following runtime files. Confirm that all 11 files were restored by UNPAK:
CERTCOM CERTMON WTESTCA WACME
WDCVDNS DCR53 DCAZ DCDSEC
WFILE WLW CACERT
CERTCOM is the command interface, and CERTMON runs the service. The W-prefixed and DC-prefixed programs perform certificate-authority, DNS, and deployment work. CACERT contains the trusted certificate authorities used for outbound TLS connections. Keep this complete set together in the installation subvolume. The supplied release information identifies the package version and checksum.
Validate the license
VALIDATE LICENSE runs in CERTCOM without a datastore or a running CERTMON process. A valid trial license reports success and its expiration date:
SUCCESS: ActivCERT license is valid.
License Type............. TRIAL
Expires.................. 10/31/2026
A missing file returns an error before any signed contents are read:
ERROR 10117 Expecting existing file name for <guardian-file> parameter
Malformed, incorrectly signed, wrong-product, wrong-system, expired trial, and licenses that are not eligible for the installed version return failure with a condition-specific diagnostic. ActivCERT does not display signed license contents or signature data.
Guardian security. Set ownership and security attributes according to site policy. Keep the datastore, credential material, and temporary work files accessible only to authorized operators and ActivCERT processes.