ActivCERT

Troubleshoot

Look up numbered command diagnostics and process-log event messages. See How to Obtain Support for submitting an unresolved problem.

If CERTCOM reports Referenced ISSUER 'test-ca' does not exist, the certificate command's ISSUER clause selected a missing issuer. Run INFO ISSUER *, then correct the reference or configure that issuer. The same pattern applies to policy, credential, target, window and DNS-provider references. CERTCOM reports the first failed lookup in command order; retry after correcting it to check the remaining references. Configuration names accept any ASCII letter case; RSA-2048 and rsa-2048 refer to the same key policy. A message without Referenced identifies the command target itself.

For a missing certificate version, use INFO CERTIFICATE <name>, VERSIONS; version numbers belong to individual certificates. For missing event, task or deployment handles, inspect the corresponding INFO collection and account for retention cleanup.

Condition

Checks

CERTMON does not start

Validate LICAC or the file named by --license; validate the datastore; check process name, CPU availability, program VPROC, log destination, and the CERTMON process log.

CERTCOM cannot open

Verify the active process name, confirm CERTMON is running, and inspect STATUS SESSION after OPEN.

ACME issuer verification fails

Check the directory URL, account key, EAB settings, DCV selection, TLS trust anchor, proxy, timeouts, network path, issuer task, recent events, and process log.

DNS-01 validation fails

Verify the configured DNS provider; check credentials, zone selection, API access, record permissions, DNS visibility, provider task, events, and process log.

ACME order does not complete

Inspect the issuer request, DNS provider state, challenge record, related tasks and events, and process log; then verify the issuer and DNS provider.

Automatic issuance does not begin

Check scheduler state and interval, certificate enablement, issuer and policy references, open tasks, and recent events.

Manual renewal is rejected

Confirm the renewal policy has MANUAL-RENEW ON and CERTMON is accepting work.

Guardian file deployment fails

Check Guardian file names, file type, replacement mode, ownership, security, target state, process log, and deployment events.

LightWave deployment fails

Check PROGRAM-FILE, derived filesystem subvolume, CERT-SPEC, passphrase credential, LWxCOM accessibility, process log, and command transcript.

WAIT reaches its timeout

Inspect STATUS TASK, INFO TASK, recent events, and the responsible process log before submitting another operation.

Target is out of sync

Compare deployed, desired, observed, and rollback versions; verify the target; then redeploy or roll back as appropriate.

Collect information for support

  • ActivCERT product version from VPROC.

  • STATUS MONITOR, STATUS PROCESS *, STATUS SCHEDULER, certificate status, and target status.

  • Relevant task, event, and deployment output.

  • CERTMON and component process logs.

  • Redacted LightWave command transcript when applicable.

  • Guardian file metadata for an affected file target.

Redaction. Remove passwords, authorization values, private keys, PKCS12 passphrases, tokens, and sensitive request bodies before sharing support material.