LogoSwissSign CLM
Getting Started

Advanced Functionalities

Bulk certificate operations with HCQL queries and metadata updates using the Horizon Client.

This page covers advanced horizon-cli capabilities: bulk operations for managing certificates at scale, and metadata updates for individual certificates.

Bulk Operations

The horizon-cli bulk commands allow mass operations on certificates matched by a Horizon Certificate Query Language (HCQL) query. All bulk commands prompt for confirmation before proceeding unless --confirm is passed.

Bulk update

Update metadata across many certificates at once.

horizon-cli bulk update \
  --query 'module equals "est" and status is valid' \
  --owner "myuser" \
  --team "myteam" \
  --labels "mylabel:myvalue" \
  --contact-email "unset"

Use the value "unset" to clear an existing field.

ParameterDescription
--queryHCQL query. The update applies to all matching certificates.
--confirmSkip the confirmation prompt.
--ownerOwner to set. Optional.
--teamTeam to set. Optional.
--labelsLabels in key:value form, comma-separated. Optional.
--contact-emailContact email to set. Optional.

Bulk migrate

Migrate certificates from one profile to another, optionally updating metadata in the same operation.

horizon-cli bulk migrate \
  --query 'module equals "est" and status is valid' \
  --profile new-est-profile \
  --team myteam \
  --labels "mylabel:myvalue"

Use "unset" to clear a field during migration.

ParameterDescription
--queryHCQL query. The migration applies to all matching certificates.
--confirmSkip the confirmation prompt.
--profileTarget profile for the migration. Required.
--ownerOwner to set. Optional.
--teamTeam to set. Optional.
--labelsLabels in key:value form, comma-separated. Optional.
--contact-emailContact email to set. Optional.

Bulk revoke

Revoke all certificates matching a query.

horizon-cli bulk revoke \
  --query 'team equals "myterminatedteam" and status is valid' \
  --confirm
ParameterDescription
--queryHCQL query. Revocation applies to all matching certificates.
--confirmSkip the confirmation prompt. Recommended for automated pipelines.

Writing HCQL queries

HCQL field names are always lowercase. Common fields:

FieldExample
statusstatus is valid
modulemodule equals "est"
teamteam equals "myteam"
ownerowner equals "myuser"
valid.untilvalid.until before "2025-01-01"

For full HCQL syntax, see the Horizon documentation or use horizon-cli translate-to-hql --help.


Updating a Certificate

The horizon-cli update-cert command modifies the metadata associated with a certificate in Horizon - owner, team, contact email, labels, and technical metadata. It does not change the certificate itself.

Requirements

To update a local certificate (one stored on the machine running the client), the profile it belongs to must have the Update (pop) common configuration permission enabled.

To update a certificate referenced on Horizon by ID, the client's API account must have update permissions on that certificate.

Usage

Interactive mode

horizon-cli update-cert --cert=/path/to/cert --key=/path/to/key --prompt

In --prompt mode, you are asked for each field. Press Enter to keep an existing value unchanged.

Non-interactive mode

Pass updated values directly. Set a field to an empty string ("") to delete it.

# Update the owner of a local certificate
horizon-cli update-cert --cert=/path/to/cert --key=/path/to/key --owner=newowner

# Remove the team from a certificate in a JKS keystore
horizon-cli update-cert --cert=/path/to/cert.jks --jks-pwd=<password> --team=""

# Update labels and metadata for a certificate in the Windows store
horizon-cli update-cert --cert=<thumbprint> \
  --labels="label1:value1,label2:value2" \
  --metadata="metadata1:value1,metadata2:value2"

# Update the contact email of a certificate referenced on Horizon by ID
horizon-cli update-cert --id=<certificate-id> --contact-email="[email protected]"

Parameter reference

General parameters

ParameterDescription
--confirmSkip the confirmation prompt after changes are computed.
--promptPrompt for all fields interactively.

Update parameters

ParameterDescription
--ownerNew owner. Use "" to delete.
--teamNew team. Use "" to delete.
--contact-emailNew contact email. Use "" to delete.
--labelsLabels in key:value form, comma-separated. Use "" to delete.
--metadataTechnical metadata in key:value form. Use "" to delete.

Local certificate selection

ParameterDescription
--certPath to the certificate (PEM, PKCS#12, JKS) or Windows store thumbprint.
--keyPath to the private key (PEM only).
--pfx-pwdPKCS#12 password.
--jks-pwdJKS password.
--jks-aliasJKS alias.
--jks-alias-pwdJKS alias password.

Remote certificate selection

ParameterDescription
--idCertificate ID on the Horizon server.

On this page