LogoSwissSign CLM
Automation Guides

Apache HTTP Server

Automate TLS certificate enrollment and renewal on Apache HTTP Server with the Horizon Client.

The Horizon Client automates the full TLS certificate lifecycle on Apache HTTP Server. The certificate, CA chain, and private key are written to the server's file system and Apache is restarted automatically after each enrollment or renewal.

Prerequisites

Setting up TLS on a new Apache server

Use init when Apache does not yet have an HTTPS configuration:

sudo horizon-cli automate init --target=apache --automation-policy=<policy>

To set up HTTPS on a non-standard port:

sudo horizon-cli automate init --target=apache --automation-policy=<policy> --port=<port>

Taking control of an existing certificate

Use enroll when Apache is already serving HTTPS. The client detects the existing certificate from the Apache configuration, re-enrolls it under the automation policy, and updates the config:

sudo horizon-cli automate enroll --target=apache --automation-policy=<policy>

To preview what the client finds without making any changes:

sudo horizon-cli automate enroll --target=apache --automation-policy=<policy> --analyze-only

Scheduled renewal

Once enrolled, run routine to check for and perform renewals:

sudo horizon-cli automate routine

Create a cron job to run this automatically:

sudo horizon-cli automate create-periodic-task

The period can be any value between 1h and 24h. The default is 6h. To remove the cron job:

sudo horizon-cli automate remove-periodic-task

Certificate storage and backup

The certificate, CA chain, and private key are stored as separate files on the file system. On each renewal:

  • The new files replace the current ones.
  • The previous files are backed up in /opt/horizon/cert/backup/.
  • The original files from before Horizon took management are always preserved.

To see which certificates are currently managed and find their IDs:

horizon-cli automate list

IDs follow the format <target>-*:<port>, for example apache-*:443.

To remove a certificate from Horizon management and restore the original, pass the ID from automate list:

sudo horizon-cli automate remove <id> --restore

For trigger-based workflows and other advanced automation configuration, refer to the Evertrust Horizon documentation.

On this page