Overview
Supported servers and commands for automating the TLS certificate lifecycle with the Horizon Client.
The Horizon Client automates the full TLS certificate lifecycle on web servers — from initial setup through ongoing renewal. Automation uses EST as the enrollment protocol. For a full protocol comparison and configuration examples, see Horizon Client - Choosing a protocol.
For profile and policy setup, see Certificate Profiles and Automation Policies. For trigger-based workflows and other advanced configuration, refer to the Evertrust Horizon documentation.
Supported servers
| Server | Platform | Guide |
|---|---|---|
| Apache HTTP Server | Linux | Apache |
| Generic (any application) | Linux, Windows | Generic |
| HAProxy | Linux | HAProxy |
| Nginx | Linux | Nginx |
| Apache Tomcat | Linux, Windows | Tomcat |
| WildFly / JBoss EAP | Linux | WildFly |
| Microsoft IIS | Windows | Windows IIS |
Commands
The horizon-cli automate command covers the full TLS certificate lifecycle on a web server:
| Subcommand | Description |
|---|---|
init | New server. Configures SSL from scratch on a server with no existing TLS setup. Writes the certificate to disk and updates the server configuration to enable HTTPS. |
enroll | Existing server. Reads the server's current TLS configuration, detects the existing certificate, re-enrolls it under the automation policy, and takes over management. Also works on servers without an existing certificate (functions like init). |
routine | Check for pending requests (e.g. WebRA), retrieve approved certificates, and perform scheduled renewals. Run this periodically via cron or a scheduled task. |
create-periodic-task | Create a periodic OS-level task (cron on Linux, Scheduled Task on Windows) to run automate routine automatically. |
To see all options for any subcommand:
horizon-cli automate <subcommand> --helpSetting up TLS on a new server
Use init when the server has no existing HTTPS configuration. The client enrolls a certificate and writes it to the server configuration:
horizon-cli automate init --target=<server> --automation-policy=<policy>Taking control of an existing server
Use enroll when the server already has HTTPS configured. The client reads the existing server configuration, detects the current certificate, re-enrolls it under the automation policy, and takes over management:
horizon-cli automate enroll --target=<server> --automation-policy=<policy>If there is no existing certificate, enroll behaves like init.
To preview what the client finds without making any changes:
horizon-cli automate enroll --target=<server> --automation-policy=<policy> --analyze-onlyInteractive enrollment with --prompt
Add --prompt to be guided through the enrollment interactively instead of passing all flags on the command line. The client will prompt for each required value in sequence:
horizon-cli automate enroll --promptRunning the routine
The routine command handles all ongoing automation:
- Renews certificates that are within the configured renewal window.
- Runs post-installation scripts.
horizon-cli automate routineThe log path is configured via the log_file setting in the client configuration file, or the HRZ_LOGFILE environment variable.
Scheduling the routine
Create a periodic task to run automate routine automatically:
horizon-cli automate create-periodic-taskThe period is a duration string (e.g. 6h, 12h). It must be between 1h and 24h, and defaults to 6h. To remove the task:
horizon-cli automate remove-periodic-task