LogoSwissSign CLM

Getting Started

What to configure first with your new Horizon CLM tenant.

Welcome to your new SwissSign Horizon CLM tenant. This page walks through, in order, everything you need to configure before you can issue your first certificate.

Already familiar with Horizon and just need a specific setting? Skip ahead to the relevant configuration guide instead of following this page top to bottom.

Step 1 — Log in and secure your account

You received your tenant URL and initial administrator credentials from SwissSign by email.

  1. Go to the tenant URL provided and log in with the local administrator account.
  2. Change the local administrator password immediately. See How do I change my password? in the FAQ.

Local account usernames and passwords are case-sensitive — enter them exactly as provided. See the default password policy for the requirements enforced on this account.

Step 2 — Connect SwissSign MPKI

Your tenant needs a PKI connector before it can request certificates from SwissSign, and a trust chain before it can validate them.

Follow Configure SwissSign MPKI to:

  • Retrieve your MPKI credentials.
  • Create the PKI connector.

Step 3 — Review your Certification Authorities

SwissSign CAs are automatically added to your instance. If you need to add any other CA — an internal CA, another public CA, and so on — or want to understand the trust-store options in more depth, see Certification Authorities.

Step 4 — Create a Certificate Profile

A certificate profile defines what can be requested: the protocol, the authorization mode, the key policy, and the structure of the certificate itself (Subject DN, SANs).

Follow Certificate Profiles to create your first profile. Recommended starting settings are provided for both public TLS and S/MIME use cases.

Step 5 — Create an Automation Policy

If certificates will be issued or renewed automatically via horizon-cli (EST), bind your certificate profile to an automation policy.

Follow Automation Policies.

Step 6 — Install Horizon Client and enroll your first certificate

Install horizon-cli on the host(s) that will request certificates, and perform your first enrollment.

See the Horizon Client overview for supported platforms and help choosing a protocol, then follow the installation guide to get started.

Next steps

Once your first certificate has been issued, you may also want to look into:

  • Expiry notifications — get alerted before certificates expire (guide coming soon).
  • Roles & Permissions — control who can request, approve, and manage certificates (guide coming soon).
  • Identity Providers — connect a corporate identity provider for SSO. See Microsoft Entra ID.

Stuck somewhere? Check the FAQ — it covers the most common configuration and troubleshooting questions.

On this page