See below for testing the pre-enrollment, enrollment, and post-enrollment flow without a live Certificate Manager.
Generating a stub CA
Run the following command to generate a stub certificate authority.
mkdir -p /tmp/harness openssl req -x509 -newkey rsa:2048 -nodes -keyout /tmp/harness/testca.key -out /tmp/harness/testca.pem -subj "/CN=CertHub Stub Test CA" -days 3650 Running the test harness
Each sample folder contains a test_harness.yml to perform the following test:
- Pre-issuance: generates the private key and CSR.
- Fake-sign: uses the local stub CA to issue a test certificate from that CSR, replacing Certificate Manager’s real enrollment service.
- Post-issuance: import, install, or deploy the test certificate.
Open a command line in a sample folder and run:
ansible-playbook test_harness.yml -i inventory.ini -u <user> -k --become -e cert_name=demo.example.com -e keystore_pass=changeitVerifying key generation
Confirm that pre-issuance generated a usable private key. For a JKS in the <path> file path, the following command should show PrivateKeyEntry.
keytool -list -keystore <path>For a PEM-encoded key in the <path> file path, run
openssl pkey -in <key> -noout -checkVerifying CSR validity
Run the following command to confirm that the CSR generated in the <path> file path is readable, cryptographically valid, and contains the expected subject.
openssl req -in <path> -noout -verify -subjectVerifying certificate import
Run the following command to confirm that post-issuance placed or imported the certificate signed by the stub CA. For a JKS, the following command should show the stub CA.
keytool -listFor a PEM-encoded certificate in the <path> file path, run the following command.
openssl x509 -in <cert> -noout -issuer