LogoSwissSign CLM
Automation Guides

Overview

Supported servers and commands for automating the TLS certificate lifecycle with the Horizon Client.

The Horizon Client automates the full TLS certificate lifecycle on web servers — from initial setup through ongoing renewal. Automation uses EST as the enrollment protocol. For a full protocol comparison and configuration examples, see Horizon Client - Choosing a protocol.

For profile and policy setup, see Certificate Profiles and Automation Policies. For trigger-based workflows and other advanced configuration, refer to the Evertrust Horizon documentation.

Supported servers

ServerPlatformGuide
Apache HTTP ServerLinuxApache
Generic (any application)Linux, WindowsGeneric
HAProxyLinuxHAProxy
NginxLinuxNginx
Apache TomcatLinux, WindowsTomcat
WildFly / JBoss EAPLinuxWildFly
Microsoft IISWindowsWindows IIS

Commands

The horizon-cli automate command covers the full TLS certificate lifecycle on a web server:

SubcommandDescription
initNew server. Configures SSL from scratch on a server with no existing TLS setup. Writes the certificate to disk and updates the server configuration to enable HTTPS.
enrollExisting server. Reads the server's current TLS configuration, detects the existing certificate, re-enrolls it under the automation policy, and takes over management. Also works on servers without an existing certificate (functions like init).
routineCheck for pending requests (e.g. WebRA), retrieve approved certificates, and perform scheduled renewals. Run this periodically via cron or a scheduled task.
create-periodic-taskCreate a periodic OS-level task (cron on Linux, Scheduled Task on Windows) to run automate routine automatically.

To see all options for any subcommand:

horizon-cli automate <subcommand> --help

Setting up TLS on a new server

Use init when the server has no existing HTTPS configuration. The client enrolls a certificate and writes it to the server configuration:

horizon-cli automate init --target=<server> --automation-policy=<policy>

Taking control of an existing server

Use enroll when the server already has HTTPS configured. The client reads the existing server configuration, detects the current certificate, re-enrolls it under the automation policy, and takes over management:

horizon-cli automate enroll --target=<server> --automation-policy=<policy>

If there is no existing certificate, enroll behaves like init.

To preview what the client finds without making any changes:

horizon-cli automate enroll --target=<server> --automation-policy=<policy> --analyze-only

Interactive enrollment with --prompt

Add --prompt to be guided through the enrollment interactively instead of passing all flags on the command line. The client will prompt for each required value in sequence:

horizon-cli automate enroll --prompt

Running the routine

The routine command handles all ongoing automation:

  • Renews certificates that are within the configured renewal window.
  • Runs post-installation scripts.
horizon-cli automate routine

The log path is configured via the log_file setting in the client configuration file, or the HRZ_LOGFILE environment variable.

Scheduling the routine

Create a periodic task to run automate routine automatically:

horizon-cli automate create-periodic-task

The period is a duration string (e.g. 6h, 12h). It must be between 1h and 24h, and defaults to 6h. To remove the task:

horizon-cli automate remove-periodic-task

On this page