Use CERTCOM to check the service, review tasks and events, and perform maintenance. Open the CERTMON service you want to manage before using these commands. Replace the sample names and task or event handles with those from your service.
Daily health check
Check that you are connected to the correct monitor. Then check its processes, scheduler, datastore, open tasks, and recent events. These commands display information without changing the service:
STATUS SESSION
STATUS MONITOR, DETAIL
STATUS PROCESS *
STATUS SCHEDULER, DETAIL
INFO DATASTORE
INFO TASK *, OPEN
INFO EVENT *, RECENT 20
A healthy service has an open session, service state RUNNING, the intended datastore, a running backup when configured, an active or intentionally frozen scheduler, and no unexplained warning or error events.
Process and worker status
List the monitor and workers to see which processes are running and handling work. Then select a process name for a detailed inspection; $ACMON is the example monitor name:
STATUS PROCESS *
STATUS PROCESS $ACMON, DETAIL
STATUS PROCESS * lists the CERTMON primary and backup processes and any workers handling open tasks. It shows the process name, program, role, CPU and PIN, whether the process is running, and the assigned task. The summary shows how many ACME, LightWave, and Guardian file worker slots are in use.
Use STATUS PROCESS <logical-name> to inspect one process. UNAVAILABLE means the expected process is no longer running. UNEXPECTED means that the process name now belongs to a different process instance. If an open task reports either state, inspect the task, events, and process log before retrying or aborting it.
Issuers and DNS providers
Check the issuers and DNS providers if certificate requests fail. INFO DCV lists all providers; the other commands show the settings for each provider type:
INFO ISSUER *
INFO DCV *
INFO DCV-ROUTE53 *
INFO DCV-AZURE *
INFO DCV-DESEC *
Investigate disabled objects, failed verification, authentication errors, DNS update errors, and ACME requests that do not advance.
Tasks
Each task has a handle, such as T000015. Handles are case-insensitive. List recent tasks, or use a handle to inspect one task and wait for it to finish:
INFO TASK *, RECENT 20
INFO TASK T000015
STATUS TASK T000015
WAIT TASK T000015, TIMEOUT 300
STATUS TASK shows the task's progress, timing, result, and any action needed. INFO TASK shows its details, including the certificate or target name.
Abort or retry only after inspecting the task and related events. ABORT requests cancellation; RETRY requests another attempt. Select the appropriate action for the task's state and the problem identified; these are alternatives, not a two-command procedure:
ABORT TASK T000015
RETRY TASK T000015
Events
Each event has a handle, such as E00002K. Handles are case-insensitive. List recent events, show only errors, or inspect one event:
INFO EVENT *, RECENT 30
INFO EVENT *, RECENT 30, SEVERITY ERROR
INFO EVENT E00002K
Events record service activity. Process logs provide more detail about the work performed by each process. Processing errors appear in both.
Deployments
Review recent deployment records to identify what reached an application target. Start with the collection, narrow it to a target, or inspect the handle of one deployment:
INFO DEPLOYMENT *, RECENT 20
INFO DEPLOYMENT *, TARGET web-files, RECENT 10
INFO DEPLOYMENT T000016
Deployment output uses target and certificate names plus decimal versions.
Process logs
Use the Event Message Reference to look up the numeric message code, severity, cause, effect and recovery.
CERTMON and every component that performs certificate work use the CERTMON log configuration. Each record identifies the component and process. Every processing error is written to the responsible process log as well as the event history. To inspect an open Guardian log file, copy it with SHARE:
FUP COPY $DATA.ACTCERT.ACLOG,, FOLD,SHARE
Export events
Export event history to a Guardian file for analysis or support. Choose CSV for tabular processing or JSON-LINES for one JSON record per line. The examples are alternative formats; the exclamation mark requests replacement of the selected destination when permitted:
EXPORT EVENT *, FILE $DATA.OUT.ACEVCSV !, FORMAT CSV
EXPORT EVENT *, FILE $DATA.OUT.ACEVJSON !, FORMAT JSON-LINES
Use RECENT and SEVERITY filters to limit collection exports.
Scheduler control
Freeze the scheduler to pause automatic work during maintenance. Check its state, and use THAW when automatic work can resume. Commands can still start work while the scheduler is frozen, so coordinate these requests with anyone performing maintenance:
FREEZE SCHEDULER, REASON 'Certificate service maintenance'
STATUS SCHEDULER, DETAIL
THAW SCHEDULER
STATUS SCHEDULER displays Last Scan and Next Scan in whole-second UTC with or without DETAIL.
INFO configuration, certificate version and deployment timestamps use YYYY-MM-DDTHH:MM:SSZ, with fractional seconds omitted without rounding. Unset values and duration fields are unchanged. Task and event detail retains microsecond precision for troubleshooting; compact task/event collections, event exports and logs retain their existing formats. Certificate, target, product and scheduler STATUS timestamps use the same whole-second display. ActivCERT retains full timestamp precision internally. Last Scan is the start time of the last completed scan, or NOT RUN before the first scan of the current monitor. Last Scan and detailed scan results are UNAVAILABLE when there is no current monitor runtime record, including after graceful shutdown. Next Scan is the monitor's recorded planned scan time, NONE while frozen or stopped, or UNAVAILABLE when a running monitor has not recorded it. DETAIL also displays the last scan result and due and blocked certificate counts.
Monitor the product license
CERTMON periodically reloads the configured license file. Validate a replacement under a different Guardian filename, then replace the active file as one complete Guardian file using the site-approved procedure. CERTMON applies a valid replacement without a restart.
A license remains current through its signed expiration date and expires at 00:00 UTC on the following day. An expired trial license prevents startup and stops a running CERTMON service. An expired non-trial license remains usable; CERTMON writes an ERROR when it detects expiration and once per hour while the license remains expired.
Validate the replacement before installation:
RUN CERTCOM VALIDATE LICENSE <replacement-license>
Deployment maintenance windows
A deployment window restricts when a target may begin deployment or rollback. Window days and start times are UTC. Issuance and renewal continue outside the window; the deployment task remains pending until the next eligible start. Work that starts inside a window runs to completion.
This example creates a weekend window, inspects it, assigns it to the existing web-files target, and submits a deployment subject to that window:
ADD DEPLOYMENT-WINDOW weekend-window, &
DAYS 'SAT,SUN', START 01:00, DURATION-MINUTES 240
INFO DEPLOYMENT-WINDOW weekend-window, DETAIL
ALTER TARGET-FILE web-files, WINDOW weekend-window
DEPLOY TARGET web-files, WAIT
Use OVERRIDE-WINDOW only for an approved immediate deployment or rollback. Choose the operation needed; the examples are alternatives. The task records the override:
DEPLOY TARGET web-files, OVERRIDE-WINDOW, WAIT
ROLLBACK TARGET web-files, OVERRIDE-WINDOW, WAIT
Periodic cleanup and retention
CERTMON periodically removes temporary work files and old records that are no longer needed. Cleanup keeps records and files still required by active tasks, current and rollback certificate versions, retries, provider operations, and retained diagnostics. Review the current retention settings before changing them:
INFO WORK-FILES
INFO CONFIGURATION, DETAIL
ALTER WORK-FILES, RETENTION 604800, CLEAN-INTERVAL 3600
ALTER CONFIGURATION, TASK-RETENTION 2592000, &
EVENT-RETENTION 7776000, ACME-ORDER-RETENTION 2592000
INFO CONFIGURATION displays retention periods, Shutdown Drain and the detailed Scheduler Interval in exact readable units, such as 1 day, 5 minutes or 61 seconds. ALTER CONFIGURATION continues to accept these settings in seconds.
Preview record cleanup before running it manually. CLEAN RECORDS removes only expired records that are no longer in use. CLEAN WORK-FILES removes only temporary files registered by ActivCERT that have reached the configured retention age:
CLEAN RECORDS, PREVIEW
CLEAN RECORDS
CLEAN WORK-FILES
Identify ACME traffic from an instance
ACME-USER-AGENT is stored in each instance's datastore. It defaults to ActivCERT and supplies the complete HTTP User-Agent value for ACME requests, including directory, account, order, challenge, certificate, and renewal-information requests. Changing it does not select a different ACME account.
The following examples set and inspect a custom identity, then reset and inspect the default. Keep the custom setting if it is the identity you intend to use:
ALTER CONFIGURATION, ACME-USER-AGENT 'ActivCERT production east'
INFO CONFIGURATION, DETAIL
ALTER CONFIGURATION, ACME-USER-AGENT *
INFO CONFIGURATION, DETAIL
The first command sets a custom identity; * resets it to ActivCERT. INFO shows the exact effective value. A custom value must contain 1 through 128 printable ASCII characters, including at least one non-space character. Quote values containing spaces. The setting survives CERTMON restart.
For multiple instances, OPEN each monitor and set its value separately:
OPEN $ACEST
ALTER CONFIGURATION, ACME-USER-AGENT 'ActivCERT production east'
OPEN $ACWST
ALTER CONFIGURATION, ACME-USER-AGENT 'ActivCERT production west'
Use site-approved non-sensitive identifiers. This value is sent to the ACME service and should contain no credentials or protected operational details.