Overview
What the Horizon Client does, supported platforms, system requirements, and protocol choice.
Horizon Client (horizon-cli) is the command-line tool for interacting with Evertrust Horizon from your own hosts. It is a single self-contained binary compiled in Go, available for Linux, Windows, macOS, and AIX.
The client covers two broad use cases:
- Certificate discovery & import - scan hosts or network ranges, import from third-party sources, and feed results into Horizon.
- Certificate lifecycle management - enroll, renew, revoke, update, and automatically install TLS certificates using EST, SCEP, or WebRA protocols.
Supported platforms
| Platform | Architecture |
|---|---|
| Linux | x86-64, arm64 |
| Windows | x86-64 |
| macOS (Darwin) | x86-64, arm64 |
| AIX | ppc64 |
System requirements
| Resource | Certificate lifecycle | Discovery |
|---|---|---|
| CPU | 1 GHz, 1+ core | 2 GHz, 2+ cores |
| RAM (Linux) | 1 GB | 2 GB |
| RAM (Windows/AIX) | 2 GB | 4 GB |
| Storage | 10 GB+ | 20 GB+ |
Choosing a protocol
All three protocols handle certificate enrollment and renewal. The right choice depends on your validation model and what operations you need:
| EST | SCEP | WebRA | |
|---|---|---|---|
| Validation model | Pre-validated | Pre-validated | Post-validated - a Horizon operator approves the request |
| Authentication modes | Authorized user, challenge password, certificate swap (x509) | Authorized user, challenge password | N/A - request is submitted and awaits operator approval |
| Key generation | Client-side (default) or server-side (--centralized) | Client-side only | Client-side only |
| Enrollment | Yes | Yes | Yes |
| Renewal | Yes | Yes | Yes |
EST is the recommended protocol. It offers the most authentication flexibility - static API credentials, one-time challenge passwords, or authentication via an existing certificate (x509 swap) - and is the only pre-validated protocol that supports server-side key generation (--centralized).
For SCEP and WebRA, refer to the Evertrust Horizon documentation.