Monitoring acme.sh - Management Hub

Hello, I am working on implementing Management Hub and have run into a snag. We have existing infrastructure using the CTW Windows client and we also use acme.sh with CTW as the DNS provider for acme-dns.

We have not been using Hub up until now. I am running the docker image for Hub 7.2.0, joining a Windows client to it worked without a hitch. I was also able to successfully join an Ubuntu box running acme.sh with the Management Agent. I gave the agent read access to ~/.acme.sh and it was able to pull the fact that there are 4 managed certificates on this particular server. However, it is not displaying details about what those managed certs are. I will attach screenshots to the post.

To troubleshoot I pointed the agent at the literal path for .acme.sh. I also enabled logging in the acme.sh conf file and pointed the Hub at the log path. Additionally, I set the agent to ‘Debug’ log level instead of the default ‘Information’. Any input? Hopefully I have not missed something in the documentation that would answer this question.

Instance totals

Windows Instance

Linux Instance

Hi,

If you review the logs for the linux instance under (the hub) Settings > System > Log (select the target instance). You should see any errors related to initializing the acme.sh reads in the system log.

The app uses a combination of the acme.sh renewal config, it’s logs and the certificate pem file. So if it can’t read any of those (as the user/group the service is running as) then you will only get partial results.

When setting read permission I tend to use setfacl.

To debug reads the service might be attempting:

Get process ID:
ps aux | grep Certify

Run a file activity trace:

sudo strace -p <pid> -f -e trace=file

Then use the refresh option in Certificate Managers to trigger a reload of the nginx provider.

Set ACL on file/folders so agent can access (e.g, read. Note directories require x for traversal):

sudo setfacl -m d:g:certify:rx target_dir