LogoSwissSign CLM
Getting Started

EST Certificate Lifecycle

Enroll and renew certificates over EST with the Horizon Client, including all parameters.

The Horizon Client enrolls and renews certificates over EST using the automate subcommand. Enrollment authenticates against an automation policy configured in Horizon, which points to an EST profile.

Authentication modes

ModeHow it works
Authorized userThe automation policy uses authorized mode. Set api_id and api_key in the configuration file. No additional flags needed at enrollment time.
Challenge passwordThe automation policy uses challenge mode. Obtain a one-time password from Horizon and pass it via --challenge. No api_id or api_key needed — useful for one-off enrollments without a dedicated service account.

Decentralized vs. centralized enrollment

ModeKey generationUse when
Decentralized (default)Client generates the private key and CSR locally. Key and certificate are stored on the client.Standard deployments where the private key should not leave the host.
Centralized (--centralized)Client sends a dummy CSR; Horizon generates the key and returns the certificate and key as a PKCS#12 bundle.The private key must be generated server-side — for example when key escrow is required.

Enrollment

Authorized user

Set api_id and api_key in the configuration file, then enroll:

horizon-cli automate enroll --automation-policy=<policy> \
  --cert=/path/to/cert.pem --key=/path/to/key.pem

Challenge password

Obtain the one-time challenge from a Horizon operator, then enroll:

horizon-cli automate enroll --automation-policy=<policy> --challenge=<challenge> \
  --cert=/path/to/cert.pem --key=/path/to/key.pem

Centralized enrollment

Use --centralized when Horizon must generate the private key server-side. Horizon returns the certificate and key as a PKCS#12 bundle, so specify --pfx and --pfx-pwd as the output:

horizon-cli automate enroll --automation-policy=<policy> --centralized --challenge=<challenge> \
  --pfx=/path/to/output.p12 --pfx-pwd=<password>

Interactive mode

Use --prompt to be guided through each required value interactively:

horizon-cli automate enroll --prompt

Preview without changes

Use --analyze-only to see what the client would do without making any changes:

horizon-cli automate enroll --automation-policy=<policy> --analyze-only

For server-specific enrollment (Nginx, Apache, IIS, Tomcat, and others), see the Automation Guides. Those guides handle server configuration detection and service restarts automatically.

Renewal

Renewal is handled automatically by the routine command. It checks all managed certificates and renews any that are within the configured renewal window:

horizon-cli automate routine

Set up a scheduled task to run this periodically — see Scheduling the routine.

Parameter reference

Enrollment parameters

ParameterDescription
--automation-policyHorizon technical name of the automation policy. Required.
--challengeOne-time challenge from Horizon (challenge mode only).
--centralizedSwitch to centralized enrollment — Horizon generates the private key and returns a PKCS#12 bundle.
--analyze-onlyPreview what the client would do without making any changes.
--promptInteractive mode — guided through each required value in sequence.
--scriptPath to a script to execute on successful enrollment (see Script parameter).

Certificate content parameters

ParameterDescription
--dnSubject DN (comma-separated elements).
--cnSubject Common Name.
--ouSubject OU (multiple values allowed).
--dnsnamesSAN DNS entries (multiple values allowed).
--ipSAN IP entries (multiple values allowed).
--emailsSAN RFC822Name entries (multiple values allowed).

Use --contact-email, --owner, --team, and --labels to assign organizational metadata to the request.

Key type (--key-type)

SyntaxExamples
rsa-<size>rsa-2048, rsa-3072, rsa-4096
ec-<curve>ec-secp256r1, ec-secp384r1, ec-secp521r1
ed-<curve>ed-Ed25519

Output parameters

ParameterDescription
--certOutput path for the certificate (PEM).
--keyOutput path for the private key (PEM).
--ca-chainOutput path for the CA chain (PEM).
--pfxOutput path for a PKCS#12 bundle.
--pfx-pwdPassword for the PKCS#12 output. Required if --pfx is set.
--pfx-aesUse AES encryption for PKCS#12 (compatible with OpenSSL v3).
--jksOutput path for a JKS keystore.
--jks-pwdJKS password. Required if --jks is set.
--jks-aliasJKS alias. Required if --jks is set.
--jks-alias-pwdJKS alias password.
--overwriteAlways overwrite existing output files.

Windows certificate store parameters

ParameterDescription
--win-user-store-authAuthenticate using the current user's Windows certificate store.
--win-computer-store-authAuthenticate using the local machine's Windows certificate store.
--win-user-store-saveSave the enrolled certificate to the user Windows certificate store.
--win-computer-store-saveSave the enrolled certificate to the machine Windows certificate store.
--win-store-use-tpmStore the key in the Microsoft Platform Crypto Provider (TPM).
--win-store-use-legacyStore the key in the legacy Microsoft Enhanced Cryptographic Provider v1.0.
--win-store-set-exportableMark the key as exportable from the Windows store.

Script parameter

Pass --script with a path to a script that is executed after a successful enrollment or renewal. The script receives four positional arguments:

  1. Issued certificate serial number
  2. Issued certificate fingerprint (SHA-1 / Windows thumbprint)
  3. Issued certificate Subject DN
  4. Issued certificate Issuer DN

Bash example:

#!/bin/sh
echo $1  # serial
echo $2  # fingerprint
echo $3  # subject
echo $4  # issuer

PowerShell example:

param($serial, $fingerprint, $subject, $issuer)
Write-Output $serial
Write-Output $fingerprint
Write-Output $subject
Write-Output $issuer

On this page