ActivCERT manages the TLS certificates used by applications on HPE Nonstop systems. It can obtain certificates from an ACME certificate authority, renew them before they expire, install them in Guardian files or LightWave, and verify the installed result. Operators use CERTCOM to configure the service and review its work. CERTMON runs continuously in the background and continues certificate operations after a process or CPU failure.
What is ACME
ACME stands for Automatic Certificate Management Environment. It is a standard way for software to request and renew TLS certificates from a certificate authority—the service that issues certificates. ACME automates the exchange that would otherwise involve submitting a certificate request, proving control of the domain names, and collecting the issued certificate.
ActivCERT acts as an ACME client. It communicates with the certificate authority's ACME service to obtain and renew certificates, then installs them for your Nonstop applications. This allows routine renewals to run without someone manually requesting and installing each replacement certificate.
An ACME service is required for ActivCERT to obtain and renew production certificates. Your certificate authority, or a certificate lifecycle management (CLM) service connected to it, must provide an ACME service compatible with ActivCERT. A CLM product is not required if your certificate authority provides ACME directly. A manual certificate ordering process alone does not provide the ACME service that ActivCERT needs.
Before planning an installation, confirm ACME availability and access requirements with your certificate authority or security team. ActivCERT's built-in test certificate authority supports training and testing only.
For more information about the standard, see ACME (RFC 8555).
What ActivCERT does
-
Keeps the certificate service available with primary and backup CERTMON processes.
-
Stores configuration, certificate history, tasks, and protected credentials in an Enscribe datastore.
-
Obtains and renews certificates through ACME services, including services that provide ACME Renewal Information (ARI).
-
Completes DNS-01 domain validation through supported DNS services including Amazon Route 53, Microsoft Azure DNS, and deSEC.
-
Provides a built-in test certificate authority for training and non-production testing.
-
Renews certificates automatically according to policy, while still allowing authorized operators to start a renewal.
-
Installs certificates in Guardian files in PEM or PKCS12 format.
-
Installs certificates in LightWave Server and LightWave Client.
-
Keeps certificate history and supports verification, redeployment, quarantine, and rollback.
-
Records tasks, events, deployments, and process logs so operators can monitor and troubleshoot the service.
The following limits apply:
-
Production certificates come from a certificate authority. ActivCERT uses an ACME service to obtain and renew them. Its built-in test certificate authority is intended only for training and testing. ActivCERT is not a production certificate issuer.
-
Certificate deployment is limited to Nonstop applications. ActivCERT installs certificates in Guardian files, LightWave Server, and LightWave Client. It does not deploy certificates to external systems such as Windows or Linux.
How ActivCERT works
CERTCOM writes configuration and operator requests to the ActivCERT datastore. The CERTMON primary process reads that work, starts a worker for the required certificate-authority, DNS, or deployment operation, and records the result. A passive CERTMON backup monitors the primary and takes over when the primary process or its CPU fails.
Figure 1 ActivCERT architecture and external connections
The following terms describe the information that operators configure and inspect. A managed certificate connects an issuer, renewal and key policies, one or more issued versions, and any destinations that receive those versions.
|
Object |
Purpose |
|---|---|
|
Datastore |
Enscribe file set containing configuration, protected credentials, certificate versions, tasks, events, and runtime state. |
|
Credential |
Named protected value used by issuers, DNS providers, certificates, or deployment targets. |
|
DNS provider |
Publishes and verifies DNS-01 challenge records through a supported provider. |
|
Issuer |
Issues certificate versions through ACME or the built-in TEST-CA. |
|
Key policy |
Controls key generation, imported keys, active-key reuse, and renewal rotation. |
|
Renewal policy |
Controls renewal timing, ARI, retries, operator renewal, and post-renewal deployment. |
|
Certificate |
Managed identity that connects an issuer, policies, subject, SANs, and targets. |
|
Version |
One issued certificate belonging to a managed certificate. Displayed versions use per-certificate numbers starting at 1. |
|
Target |
Destination that receives a certificate version: Guardian files, LightWave Server, or LightWave Client. |
|
Task |
Persistent operation such as issuance, renewal, deployment, verification, or rollback. |
|
Event |
Timestamped operational record that explains service and task activity. |
How ActivCERT manages a certificate
-
Create the ActivCERT datastore and start the CERTMON process pair.
-
Store the required credentials and configure an ACME issuer or the built-in test certificate authority.
-
Choose how ActivCERT creates private keys and when it renews certificates.
-
Add the certificate name, subject, and subject alternative names that the application needs.
-
Add the Guardian file or LightWave destinations that should receive the certificate.
-
Obtain the first certificate from the selected issuer, or adopt an existing installation.
-
Let the scheduler renew and install the certificate automatically, or start an operation from CERTCOM.
-
Use status, task, event, deployment, and process-log information to monitor each operation.
-
Verify the installed certificate and redeploy or roll back when necessary.