Generic
Enroll and renew certificates to disk for any application the Horizon Client does not natively support.
The generic target enrolls and renews a TLS certificate without targeting a specific web server. Use it for applications that are not natively supported, custom services that read certificates from a specific file path, or any scenario where you need a certificate written to disk without auto-configuring a server.
The generic target is supported on both Linux and Windows.
Prerequisites
- Horizon Client installed and configured (see Installation & Configuration)
- A PKI connector configured in Horizon. See Configure SwissSign MPKI.
- A certificate profile configured in Horizon. See Certificate Profiles.
- An automation policy configured in Horizon. See Automation Policies.
Setting up a new certificate
Use init to enroll a new certificate and write it to disk. Certificates are written to a default location unless you specify otherwise:
- Linux:
/opt/horizon/var/generic - Windows:
C:\ProgramData\EverTrust\Horizon\Var\Generic
PEM files (cert, chain, key)
horizon-cli automate init --target=generic --automation-policy=<policy> \
--cert=my_cert.pem --key=my_key.pem --chain-file=my_chain.pem --no-interactivePKCS#12 bundle
horizon-cli automate init --target=generic --automation-policy=<policy> \
--pfx=my_cert.p12 --pfx-pwd=<password> --no-interactiveWindows certificate store (Windows only)
horizon-cli.exe automate init --target=generic --automation-policy=<policy> --win-computer-store --no-interactiveUse --win-user-store instead to store in the current user's store rather than the machine store.
Custom output location
Use --config-folder to write files to a different directory:
horizon-cli automate init --target=generic --automation-policy=<policy> \
--config-folder=/path/to/folder --cert=my_cert.pem --key=my_key.pem --chain-file=my_chain.pem --no-interactiveInteractive mode
If you prefer to be guided through the options:
horizon-cli automate init --target=generic --promptTaking control of an existing certificate
Use enroll to bring a certificate that already exists on disk under Horizon management. Unlike server-specific targets, the generic target has no server configuration to auto-detect from, so you must specify the file paths explicitly — the same flags as init:
# PEM files
horizon-cli automate enroll --target=generic --automation-policy=<policy> \
--cert=my_cert.pem --key=my_key.pem --chain-file=my_chain.pem --no-interactive
# PKCS#12 bundle
horizon-cli automate enroll --target=generic --automation-policy=<policy> \
--pfx=my_cert.p12 --pfx-pwd=<password> --no-interactiveTo preview what the client finds without making any changes:
horizon-cli automate enroll --target=generic --automation-policy=<policy> \
--cert=my_cert.pem --key=my_key.pem --no-interactive --analyze-onlyScheduled renewal
Once enrolled, run routine to check for and perform renewals:
horizon-cli automate routineCreate a periodic task to run this automatically:
# Linux
sudo horizon-cli automate create-periodic-task
# Windows
horizon-cli.exe automate create-periodic-taskThe period can be any value between 1h and 24h. The default is 6h. To remove the task:
horizon-cli automate remove-periodic-taskManaging enrolled certificates
To see which certificates are currently managed and find their IDs:
horizon-cli automate listIDs follow the format <target>-*:<port>, for example generic-*:443.
To remove a certificate from Horizon management and restore the original, pass the ID from automate list:
horizon-cli automate remove <id> --restoreFor trigger-based workflows and other advanced automation configuration, refer to the Evertrust Horizon documentation.