ActivCERT

Manage certificates and versions

Use CERTCOM to view certificates, obtain or renew them, and manage their versions. Open your CERTMON service before entering these commands. Replace web-server in the examples with your certificate name.

Inspect certificate state

Use INFO to view a certificate's configuration and history, and STATUS to check its current status. HISTORY shows its activity, VERSIONS lists the saved versions, and VERSION displays one version:

INFO CERTIFICATE web-server, DETAIL
STATUS CERTIFICATE web-server, DETAIL
INFO CERTIFICATE web-server, HISTORY
INFO CERTIFICATE web-server, VERSION 1, DETAIL
INFO CERTIFICATE web-server, VERSIONS

Each certificate has its own version numbers, starting at 1.

ActivCERT assigns the next number when a version is successfully stored. Each certificate has its own sequence. Retrying work that already stored a version keeps that number. Retention can remove older versions; surviving versions keep their numbers and subsequent versions continue above the highest assigned number. Failed work that stores no version consumes no number.

VERSIONS lists the retained versions for the named certificate. VERSION selects one of those versions. HISTORY displays task and event history.

Always include the certificate name when selecting a version. Use a positive version number, such as VERSION 1. INFO VERSION and ALTER VERSION are not valid commands on their own, and VERSION does not accept V-prefixed handles or internal unique IDs.

Every INFO command accepts DETAIL. It shows additional information where available; otherwise it shows the normal output. Queries using * still display a summary table. Other unsupported options produce an error. Named INFO CERTIFICATE output includes the configured issuer, renewal policy, and key policy. These references identify the configuration used for future work.

The detailed version view reports Issuance Source as EXTERNAL for an imported version, ACME for a version obtained through an ACME account, TEST-CA for a version issued by the built-in test authority.

Use LINKS to inspect the certificate's relationships with its issuer, policies, credentials, and deployment targets:

INFO CERTIFICATE web-server, LINKS

LINKS shows the issuer, credentials, policies, DNS provider, targets, and current version used by the certificate. Credential names are shown, but secret values are hidden. UNAVAILABLE means that a related item was deleted or could not be read; the other items are still displayed.

For an ACME issuer, Account Key names the ACME-ACCOUNT-KEY credential used to sign account requests; EAB Secret names the separate EAB-SECRET credential used during external account binding. The output includes credential names, types, and status, while protected values remain hidden. A generated account key appears after account setup has stored it.

With DCV EXTERNAL, the relationship view identifies external validation and does not report a missing DNS-provider credential. With a named provider, it shows the provider and its credential roles. Inspect an UNAVAILABLE object before requesting work.

Issue the first version

When the scheduler is running, it obtains certificates that do not yet have a version. To obtain the first version yourself, use ISSUE:

ISSUE CERTIFICATE web-server, WAIT

WAIT waits for issuance and any selected deployments to finish, or until the wait times out.

Initial issuance selects enabled targets with DEPLOY-AFTER-RENEW ON when the renewal policy also has DEPLOY-AFTER-RENEW ON (the default). This applies to both explicit ISSUE and scheduler-submitted issuance. Deployment windows remain in effect; issuance can activate a version while its deployment is still pending.

Renew

CERTMON renews certificates automatically when they are due and the scheduler is running. You do not need to enter RENEW for automatic renewal. To renew a due certificate yourself, its policy must have MANUAL-RENEW ON:

RENEW CERTIFICATE web-server, WAIT

FORCE bypasses the due-state check for an approved operational test or replacement:

RENEW CERTIFICATE web-server, FORCE, WAIT

The renewal policy must have MANUAL-RENEW ON for operator-initiated renewal. With DEPLOY-AFTER-RENEW ON, selected targets are deployed and verified as part of the renewal lifecycle.

Inspect ACME requests

ACME issuance and renewal records show account, order, authorization, challenge, and certificate progress without displaying protected credential values.

Inspect the related task handle and recent events:

INFO TASK <task-handle>, DETAIL
STATUS TASK <task-handle>
INFO EVENT *, RECENT 20

Quarantine a version

Prevent a known-bad version from being selected for deployment:

Quarantine requires a certificate name and an explicit version number. Confirm the selected version with INFO CERTIFICATE before changing its quarantine state.

ALTER CERTIFICATE web-server, VERSION 2, QUARANTINE ON, REASON 'Verification failed'

Remove quarantine only after the version is safe to use:

ALTER CERTIFICATE web-server, VERSION 2, QUARANTINE OFF