EST Certificate Lifecycle
Enroll and renew certificates over EST with the Horizon Client, including all parameters.
The Horizon Client enrolls and renews certificates over EST using the automate subcommand. Enrollment authenticates against an automation policy configured in Horizon, which points to an EST profile.
Authentication modes
| Mode | How it works |
|---|---|
| Authorized user | The automation policy uses authorized mode. Set api_id and api_key in the configuration file. No additional flags needed at enrollment time. |
| Challenge password | The automation policy uses challenge mode. Obtain a one-time password from Horizon and pass it via --challenge. No api_id or api_key needed — useful for one-off enrollments without a dedicated service account. |
Decentralized vs. centralized enrollment
| Mode | Key generation | Use when |
|---|---|---|
| Decentralized (default) | Client generates the private key and CSR locally. Key and certificate are stored on the client. | Standard deployments where the private key should not leave the host. |
Centralized (--centralized) | Client sends a dummy CSR; Horizon generates the key and returns the certificate and key as a PKCS#12 bundle. | The private key must be generated server-side — for example when key escrow is required. |
Enrollment
Authorized user
Set api_id and api_key in the configuration file, then enroll:
horizon-cli automate enroll --automation-policy=<policy> \
--cert=/path/to/cert.pem --key=/path/to/key.pemChallenge password
Obtain the one-time challenge from a Horizon operator, then enroll:
horizon-cli automate enroll --automation-policy=<policy> --challenge=<challenge> \
--cert=/path/to/cert.pem --key=/path/to/key.pemCentralized enrollment
Use --centralized when Horizon must generate the private key server-side. Horizon returns the certificate and key as a PKCS#12 bundle, so specify --pfx and --pfx-pwd as the output:
horizon-cli automate enroll --automation-policy=<policy> --centralized --challenge=<challenge> \
--pfx=/path/to/output.p12 --pfx-pwd=<password>Interactive mode
Use --prompt to be guided through each required value interactively:
horizon-cli automate enroll --promptPreview without changes
Use --analyze-only to see what the client would do without making any changes:
horizon-cli automate enroll --automation-policy=<policy> --analyze-onlyFor server-specific enrollment (Nginx, Apache, IIS, Tomcat, and others), see the Automation Guides. Those guides handle server configuration detection and service restarts automatically.
Renewal
Renewal is handled automatically by the routine command. It checks all managed certificates and renews any that are within the configured renewal window:
horizon-cli automate routineSet up a scheduled task to run this periodically — see Scheduling the routine.
Parameter reference
Enrollment parameters
| Parameter | Description |
|---|---|
--automation-policy | Horizon technical name of the automation policy. Required. |
--challenge | One-time challenge from Horizon (challenge mode only). |
--centralized | Switch to centralized enrollment — Horizon generates the private key and returns a PKCS#12 bundle. |
--analyze-only | Preview what the client would do without making any changes. |
--prompt | Interactive mode — guided through each required value in sequence. |
--script | Path to a script to execute on successful enrollment (see Script parameter). |
Certificate content parameters
| Parameter | Description |
|---|---|
--dn | Subject DN (comma-separated elements). |
--cn | Subject Common Name. |
--ou | Subject OU (multiple values allowed). |
--dnsnames | SAN DNS entries (multiple values allowed). |
--ip | SAN IP entries (multiple values allowed). |
--emails | SAN RFC822Name entries (multiple values allowed). |
Use --contact-email, --owner, --team, and --labels to assign organizational metadata to the request.
Key type (--key-type)
| Syntax | Examples |
|---|---|
rsa-<size> | rsa-2048, rsa-3072, rsa-4096 |
ec-<curve> | ec-secp256r1, ec-secp384r1, ec-secp521r1 |
ed-<curve> | ed-Ed25519 |
Output parameters
| Parameter | Description |
|---|---|
--cert | Output path for the certificate (PEM). |
--key | Output path for the private key (PEM). |
--ca-chain | Output path for the CA chain (PEM). |
--pfx | Output path for a PKCS#12 bundle. |
--pfx-pwd | Password for the PKCS#12 output. Required if --pfx is set. |
--pfx-aes | Use AES encryption for PKCS#12 (compatible with OpenSSL v3). |
--jks | Output path for a JKS keystore. |
--jks-pwd | JKS password. Required if --jks is set. |
--jks-alias | JKS alias. Required if --jks is set. |
--jks-alias-pwd | JKS alias password. |
--overwrite | Always overwrite existing output files. |
Windows certificate store parameters
| Parameter | Description |
|---|---|
--win-user-store-auth | Authenticate using the current user's Windows certificate store. |
--win-computer-store-auth | Authenticate using the local machine's Windows certificate store. |
--win-user-store-save | Save the enrolled certificate to the user Windows certificate store. |
--win-computer-store-save | Save the enrolled certificate to the machine Windows certificate store. |
--win-store-use-tpm | Store the key in the Microsoft Platform Crypto Provider (TPM). |
--win-store-use-legacy | Store the key in the legacy Microsoft Enhanced Cryptographic Provider v1.0. |
--win-store-set-exportable | Mark the key as exportable from the Windows store. |
Script parameter
Pass --script with a path to a script that is executed after a successful enrollment or renewal. The script receives four positional arguments:
- Issued certificate serial number
- Issued certificate fingerprint (SHA-1 / Windows thumbprint)
- Issued certificate Subject DN
- Issued certificate Issuer DN
Bash example:
#!/bin/sh
echo $1 # serial
echo $2 # fingerprint
echo $3 # subject
echo $4 # issuerPowerShell example:
param($serial, $fingerprint, $subject, $issuer)
Write-Output $serial
Write-Output $fingerprint
Write-Output $subject
Write-Output $issuer