Skip to main content

Prepare your automation environment with dc-acmectl

dc-acmectl is a pre-automation diagnostics tool that scans and evaluates your web server to determine compatibility and readiness for TLS/SSL certificate automation. This diagnostics tool helps you prepare and troubleshoot your server environment when configuring TLS/SSL automation through CertCentral.

You place the diagnostics tool on your server and run it from your terminal or command line. The tool:

  • Confirms environment compatibility and status

  • Identifies possible automation obstacles

  • Updates your environment and server settings, with your approval *

  • Generates a detailed diagnostic report for review

Anmerkung

*NOTE: The diagnostics tool takes read-only actions for the scan and evaluation. When the tool identifies a specific issue that may block automation, you are able to review each issue and permit the diagnostics tool to fix it on a case-by-case basis.

Diagnostics checks

What does this tool check?

The dc-acmectl diagnostics tool checks these architecture and configuration areas:

  • Host server prerequisites, such as operating system, server platform, architecture, permissions, system time, and required paths

  • Connectivity for DNS resolution, HTTPS support, and DigiCert ACME endpoints

  • Proxy settings such as proxy variables, WinHTTP proxy, and proxy bypass issues

  • Filesystem and paths for required DigiCert paths, log directories, socket files, and disk/path access

  • HTTP-01 diagnostics such as domain DNS, Apache/Nginx/IIS readiness, and HTTP validation path

  • DNS-01 diagnostics such as DNS provider support, provider API connectivity, and DNS zone/TXT readiness

  • ACME log analysis where the diagnostics tool reads the ACME client logs and identifies known failure patterns

  • Certificate installation where the diagnostics tool checks for certificate output and install issues

  • Windows IIS / HTTP.SYS for IIS bindings, HTTPS bindings, and SSL certificate binding issues

What will this tool change?

The diagnostics tool is capable of making many types of changes in your environment, so you don’t have to do them manually. However, each system change requires consent from you during the readiness check. dc-acmectl does not take action unless you approve a recommended change. The tool also will not read or display sensitive values, such as EAB credentials.

Examples of actions that require your consent:

  • Install missing dependencies such as curl or unzip

  • Start a stopped DigiCert ACME client service

  • Create Apache or Nginx configuration templates

  • Enable Apache or Nginx site configuration

  • Add IIS HTTPS site bindings

  • Create temporary self-signed certificates for IIS binding repair

  • Attach a certificate to an IIS binding

Download the diagnostics tool

Download the dc-acmectl diagnostics tool for your operating system:

Run the diagnostics tool

When you have the correct version for your operating system, copy the tool to your server and run the tool.

Run on Linux

  • Untar the downloaded file and add the tool to any local writable directory, for example: /home, /tmp, /opt/digicert

  • Run with sudo: sudo ./dc-acmectl

  • Make the binary executable, if needed: chmod +x ./dc-acmectl

Run on Windows

  • Unzip the downloaded file and add to any local writable directory, for example: Desktop, C:\Temp\dc-acmectl

  • Run as an Administrator in PowerShell or command prompt : .\dc-acmectl.exe

Commands

Check version

Current version: 1.1.0

  • Linux: ./dc-acmectl --version

  • Windows: .\dc-acmectl.exe --version

Run the dc-acmectl tool

  • Linux: sudo ./dc-acmectl

  • Windows: .\dc-acmectl.exe

Enable verbose mode

Show all results, including pass, fail, warn, info, and skip.

  • Linux: sudo ./dc-acmectl -v

  • Windows: .\dc-acmectl.exe -v

Change diagnostics log file location

By default, the tool creates a log file in the same directory where the tool is executed. To generate the file in another specific location:

  • Linux: sudo ./dc-acmectl -report-log /tmp/dc-acmectl-report.log

  • Windows: .\dc-acmectl.exe -report-log C:\Temp\dc-acmectl-report.log

Provide ACME client log file

If you have already run the automation command (generated in CertCentral) and installed the ACME client, the client created log files that can be read and used for troubleshooting.

By default, the dc-acmectl diagnostics tool refers to the default location for the ACME client log file:

  • Linux: /var/digicert/acme-client/log/dc-acme.log

  • Windows: C:\Program Files\DigiCert\AcmeClient\log\dc-acme.log

To read and analyze a different log file:

  • Linux: sudo ./dc-acmectl -log /var/digicert/acme-client/log/dc-acme.log

  • Windows: .\dc-acmectl.exe -log "C:\Program Files\DigiCert\dc-acme.log"

Show help

  • Linux: ./dc-acmectl -h

  • Windows: .\dc-acmectl.exe -h