LogoSwissSign CLM
Getting Started

Overview

What the Horizon Client does, supported platforms, system requirements, and protocol choice.

Horizon Client (horizon-cli) is the command-line tool for interacting with Evertrust Horizon from your own hosts. It is a single self-contained binary compiled in Go, available for Linux, Windows, macOS, and AIX.

The client covers two broad use cases:

  • Certificate discovery & import - scan hosts or network ranges, import from third-party sources, and feed results into Horizon.
  • Certificate lifecycle management - enroll, renew, revoke, update, and automatically install TLS certificates using EST, SCEP, or WebRA protocols.

Supported platforms

PlatformArchitecture
Linuxx86-64, arm64
Windowsx86-64
macOS (Darwin)x86-64, arm64
AIXppc64

System requirements

ResourceCertificate lifecycleDiscovery
CPU1 GHz, 1+ core2 GHz, 2+ cores
RAM (Linux)1 GB2 GB
RAM (Windows/AIX)2 GB4 GB
Storage10 GB+20 GB+

Choosing a protocol

All three protocols handle certificate enrollment and renewal. The right choice depends on your validation model and what operations you need:

ESTSCEPWebRA
Validation modelPre-validatedPre-validatedPost-validated - a Horizon operator approves the request
Authentication modesAuthorized user, challenge password, certificate swap (x509)Authorized user, challenge passwordN/A - request is submitted and awaits operator approval
Key generationClient-side (default) or server-side (--centralized)Client-side onlyClient-side only
EnrollmentYesYesYes
RenewalYesYesYes

EST is the recommended protocol. It offers the most authentication flexibility - static API credentials, one-time challenge passwords, or authentication via an existing certificate (x509 swap) - and is the only pre-validated protocol that supports server-side key generation (--centralized).

For SCEP and WebRA, refer to the Evertrust Horizon documentation.

On this page