Prepare your automation environment with dc-acmectl
dc-acmectl is a pre-automation diagnostics tool that scans and evaluates your web server to determine compatibility and readiness for TLS/SSL certificate automation. This diagnostics tool helps you prepare and troubleshoot your server environment when configuring TLS/SSL automation through CertCentral.
You place the diagnostics tool on your server and run it from your terminal or command line. The tool:
Confirms environment compatibility and status
Identifies possible automation obstacles
Updates your environment and server settings, with your approval *
Generates a detailed diagnostic report for review
Nota
*NOTE: The diagnostics tool takes read-only actions for the scan and evaluation. When the tool identifies a specific issue that may block automation, you are able to review each issue and permit the diagnostics tool to fix it on a case-by-case basis.
Diagnostics checks
What does this tool check?
The dc-acmectl diagnostics tool checks these architecture and configuration areas:
Host server prerequisites, such as operating system, server platform, architecture, permissions, system time, and required paths
Connectivity for DNS resolution, HTTPS support, and DigiCert ACME endpoints
Proxy settings such as proxy variables, WinHTTP proxy, and proxy bypass issues
Filesystem and paths for required DigiCert paths, log directories, socket files, and disk/path access
HTTP-01 diagnostics such as domain DNS, Apache/Nginx/IIS readiness, and HTTP validation path
DNS-01 diagnostics such as DNS provider support, provider API connectivity, and DNS zone/TXT readiness
ACME log analysis where the diagnostics tool reads the ACME client logs and identifies known failure patterns
Certificate installation where the diagnostics tool checks for certificate output and install issues
Windows IIS / HTTP.SYS for IIS bindings, HTTPS bindings, and SSL certificate binding issues
What will this tool change?
The diagnostics tool is capable of making many types of changes in your environment, so you don’t have to do them manually. However, each system change requires consent from you during the readiness check. dc-acmectl does not take action unless you approve a recommended change. The tool also will not read or display sensitive values, such as EAB credentials.
Examples of actions that require your consent:
Install missing dependencies such as curl or unzip
Start a stopped DigiCert ACME client service
Create Apache or Nginx configuration templates
Enable Apache or Nginx site configuration
Add IIS HTTPS site bindings
Create temporary self-signed certificates for IIS binding repair
Attach a certificate to an IIS binding
Download the diagnostics tool
Download the dc-acmectl diagnostics tool for your operating system:
Run the diagnostics tool
When you have the correct version for your operating system, copy the tool to your server and run the tool.
Run on Linux
Untar the downloaded file and add the tool to any local writable directory, for example:
/home,/tmp,/opt/digicertRun with
sudo:sudo ./dc-acmectlMake the binary executable, if needed:
chmod +x ./dc-acmectl
Run on Windows
Unzip the downloaded file and add to any local writable directory, for example:
Desktop,C:\Temp\dc-acmectlRun as an Administrator in PowerShell or command prompt :
.\dc-acmectl.exe
Commands
Check version
Current version: 1.1.0
Linux:
./dc-acmectl --versionWindows:
.\dc-acmectl.exe --version
Run the dc-acmectl tool
Linux:
sudo ./dc-acmectlWindows:
.\dc-acmectl.exe
Enable verbose mode
Show all results, including pass, fail, warn, info, and skip.
Linux:
sudo ./dc-acmectl -vWindows:
.\dc-acmectl.exe -v
Change diagnostics log file location
By default, the tool creates a log file in the same directory where the tool is executed. To generate the file in another specific location:
Linux:
sudo ./dc-acmectl -report-log /tmp/dc-acmectl-report.logWindows:
.\dc-acmectl.exe -report-log C:\Temp\dc-acmectl-report.log
Provide ACME client log file
If you have already run the automation command (generated in CertCentral) and installed the ACME client, the client created log files that can be read and used for troubleshooting.
By default, the dc-acmectl diagnostics tool refers to the default location for the ACME client log file:
Linux:
/var/digicert/acme-client/log/dc-acme.logWindows:
C:\Program Files\DigiCert\AcmeClient\log\dc-acme.log
To read and analyze a different log file:
Linux:
sudo ./dc-acmectl -log /var/digicert/acme-client/log/dc-acme.logWindows:
.\dc-acmectl.exe -log "C:\Program Files\DigiCert\dc-acme.log"
Show help
Linux:
./dc-acmectl -hWindows:
.\dc-acmectl.exe -h