LogoSwissSign CLM
Configuration

Automation Policies

Create the automation and execution policies the Horizon Client uses to enroll and renew certificates.

An automation policy is what the Horizon Client references via --automation-policy=<policy>. It binds an EST, SCEP, or ACME profile to a set of compliance rules, and optionally restricts when the client is allowed to perform renewals.

Prerequisites

  • At least one certificate profile for the enrollment protocol you want to use. See Certificate Profiles.

Step 1 — Create an execution policy (optional)

An execution policy defines time windows when the Horizon Client is allowed to perform automated actions — renewals and post-renewal restarts. Use one to prevent service disruptions during business hours.

If no execution policy is assigned to an automation policy, renewals run at any time.

The Horizon Client runs automate routine on a fixed interval (default: every 6 hours). Each time it runs, it checks whether any managed certificate is due for renewal. If a certificate is due and the current time falls inside an authorized period (and outside any forbidden period), the renewal is executed. If the time is outside the authorized window, the routine exits without renewing and waits for the next scheduled run.

This means an execution policy does not change when the client wakes up — it only controls whether a pending renewal is allowed to proceed at that moment.

  1. In Horizon, go to Automation > Execution Policy.
  2. Click Add.
  3. Fill in the fields:
FieldDescription
NameUnique identifier for this execution policy. Choose a name you can recognize later (e.g. no-business-hours). Names cannot be changed after creation.
DescriptionOptional note shown in the policy list.
Authorized periodsTime windows when automation is permitted. Leave empty to permit all times. Each period has a date range, time range, and day-of-week selector.
Forbidden periodsTime windows when automation is blocked, even if an authorized period overlaps. Useful for blocking specific maintenance windows or holidays.
  1. Click Save.

Step 2 — Create an automation policy

  1. In Horizon, go to Automation > Automation Policy.
  2. Click Add.
  3. Fill in the fields:
FieldDescription
NameUnique identifier. This is the value you pass to --automation-policy in horizon-cli commands. Names cannot be changed after creation.
ProfileThe EST, SCEP, or ACME profile to use for enrollment. Key types and crypto settings are inherited from the profile's Crypto Policy.
Execution policy(Optional) Restricts when renewals are permitted. If not set, renewals run at any time.
Authorized CAs(Optional) Certificates are only considered compliant if their issuer is in this list. Leave empty to allow all issuing CAs.
Authorized hash algorithms(Optional) Certificates are only considered compliant if their signature algorithm is in this list. Leave empty to allow all algorithms.
Trust chains(Optional) CA chains to install on the host alongside the certificate. If not set, only the chain required by the server is installed.
  1. Click Save.

Using an automation policy

Pass the policy name to any horizon-cli automate command:

horizon-cli automate init --target=<server> --automation-policy=<policy>
horizon-cli automate enroll --target=<server> --automation-policy=<policy>

For a full walkthrough of setting up TLS automation, see the Automation Guides.

On this page