See below for testing the pre-enrollment, enrollment, and post-enrollment flow without a live Certificate Manager.

Generating a stub CA

Run the following command to generate a stub certificate authority.

mkdir -p /tmp/harness
openssl req -x509 -newkey rsa:2048 -nodes -keyout /tmp/harness/testca.key -out /tmp/harness/testca.pem -subj "/CN=CertHub Stub Test CA" -days 3650

Running the test harness

Each sample folder contains a test_harness.yml to perform the following test:

  • Pre-issuance: generates the private key and CSR.
  • Fake-sign: uses the local stub CA to issue a test certificate from that CSR, replacing Certificate Manager’s real enrollment service.
  • Post-issuance: import, install, or deploy the test certificate.

Open a command line in a sample folder and run:

ansible-playbook test_harness.yml -i inventory.ini -u <user> -k --become -e cert_name=demo.example.com -e keystore_pass=changeit

Verifying key generation

Confirm that pre-issuance generated a usable private key. For a JKS in the <path> file path, the following command should show PrivateKeyEntry.

keytool -list -keystore <path>

For a PEM-encoded key in the <path> file path, run

openssl pkey -in <key> -noout -check

Verifying CSR validity

Run the following command to confirm that the CSR generated in the <path> file path is readable, cryptographically valid, and contains the expected subject.

openssl req -in <path> -noout -verify -subject

Verifying certificate import

Run the following command to confirm that post-issuance placed or imported the certificate signed by the stub CA.  For a JKS, the following command should show the stub CA.

keytool -list

For a PEM-encoded certificate in the <path> file path, run the following command.

openssl x509 -in <cert> -noout -issuer