LogoSwissSign CLM
Automation Guides

Generic

Enroll and renew certificates to disk for any application the Horizon Client does not natively support.

The generic target enrolls and renews a TLS certificate without targeting a specific web server. Use it for applications that are not natively supported, custom services that read certificates from a specific file path, or any scenario where you need a certificate written to disk without auto-configuring a server.

The generic target is supported on both Linux and Windows.

Prerequisites

Setting up a new certificate

Use init to enroll a new certificate and write it to disk. Certificates are written to a default location unless you specify otherwise:

  • Linux: /opt/horizon/var/generic
  • Windows: C:\ProgramData\EverTrust\Horizon\Var\Generic

PEM files (cert, chain, key)

horizon-cli automate init --target=generic --automation-policy=<policy> \
  --cert=my_cert.pem --key=my_key.pem --chain-file=my_chain.pem --no-interactive

PKCS#12 bundle

horizon-cli automate init --target=generic --automation-policy=<policy> \
  --pfx=my_cert.p12 --pfx-pwd=<password> --no-interactive

Windows certificate store (Windows only)

horizon-cli.exe automate init --target=generic --automation-policy=<policy> --win-computer-store --no-interactive

Use --win-user-store instead to store in the current user's store rather than the machine store.

Custom output location

Use --config-folder to write files to a different directory:

horizon-cli automate init --target=generic --automation-policy=<policy> \
  --config-folder=/path/to/folder --cert=my_cert.pem --key=my_key.pem --chain-file=my_chain.pem --no-interactive

Interactive mode

If you prefer to be guided through the options:

horizon-cli automate init --target=generic --prompt

Taking control of an existing certificate

Use enroll to bring a certificate that already exists on disk under Horizon management. Unlike server-specific targets, the generic target has no server configuration to auto-detect from, so you must specify the file paths explicitly — the same flags as init:

# PEM files
horizon-cli automate enroll --target=generic --automation-policy=<policy> \
  --cert=my_cert.pem --key=my_key.pem --chain-file=my_chain.pem --no-interactive

# PKCS#12 bundle
horizon-cli automate enroll --target=generic --automation-policy=<policy> \
  --pfx=my_cert.p12 --pfx-pwd=<password> --no-interactive

To preview what the client finds without making any changes:

horizon-cli automate enroll --target=generic --automation-policy=<policy> \
  --cert=my_cert.pem --key=my_key.pem --no-interactive --analyze-only

Scheduled renewal

Once enrolled, run routine to check for and perform renewals:

horizon-cli automate routine

Create a periodic task to run this automatically:

# Linux
sudo horizon-cli automate create-periodic-task

# Windows
horizon-cli.exe automate create-periodic-task

The period can be any value between 1h and 24h. The default is 6h. To remove the task:

horizon-cli automate remove-periodic-task

Managing enrolled certificates

To see which certificates are currently managed and find their IDs:

horizon-cli automate list

IDs follow the format <target>-*:<port>, for example generic-*:443.

To remove a certificate from Horizon management and restore the original, pass the ID from automate list:

horizon-cli automate remove <id> --restore

For trigger-based workflows and other advanced automation configuration, refer to the Evertrust Horizon documentation.

On this page