LogoSwissSign CLM
Configuration

Certification Authorities

Configure the trust store of your CLM environment.

The Certification Authorities settings define the trust store of the CLM application. This is where you register every CA that Horizon needs to know about, and where you declare what each CA is trusted for.

A single CA entry can play one or more of the following roles:

  • Trust chain material — CA certificates that may need to be included in the certificate bundle downloaded by an end user, so the issued certificate validates against a complete chain.
  • Server authentication trust — CAs that must be trusted when Horizon reaches an external system over TLS (datasources, an F5 load balancer, REST endpoints, LDAP servers, etc.).
  • Client authentication trust — CAs that must be trusted when a client presents a certificate to Horizon, for instance X.509 client authentication for local login, or the EST protocol.

Trust chains can additionally be exposed on the Registration Authority (RA), allowing end users to download the chain directly from the RA interface.

By default, the system trusts valid certificate chains issued by public CAs for server authentication. You may still need to add the full chain if you require complete trust chain material for certificate bundles, or need it for client authentication trust.

Prerequisites

You will need each Certification Authority beforehand, in one of these formats:

  • a certificate file (PEM or DER) or a certificate string (PEM).
  • its revocation endpoint URL (DER, HTTP only)

How to configure a Certification Authority

  1. In Horizon, go to Certificate Authorities.
  2. Click the Add (+) button.

The wizard walks through three tabs: Certificate → Details → Configuration.

Certificate tab

Provide the CA certificate, either by:

  • pasting the certificate string (PEM), or
  • importing the certificate file (PEM or DER).

Then click Next.

Details tab

Review the information parsed from your CA certificate (subject, issuer, validity, key usage, etc.) to confirm you imported the right CA. Then click Next.

Configuration tab

Fill in the settings below, then click Import.

FieldTypeDescription
Name (required)stringA meaningful, unique name for the Certification Authority.
OCSP responder URL (optional)stringURL of the OCSP responder, if available.
CRL URL (optional)stringURL to download the CRL (HTTP).
Outdated Revocation Status Policy (required)selectBehavior when the CRL/OCSP cannot be reached and revocation data is stale. For production environments, "Revoked" is recommended.
Refresh Periodfinite durationHow often the CRL or OCSP status is refreshed. Must be a valid finite duration. Recommended value: between 1h and 24h.
ProxyselectThe HTTP/HTTPS proxy used to reach the CRL or OCSP responder, if one is required.
Timeoutfinite durationConnection timeout when reaching the CRL or OCSP endpoint. Must be a valid finite duration.
Trusted for server authenticationbooleanTrust this CA for SSL/TLS server trust, i.e. when CLM connects out to an external system (datasource, F5 load balancer, REST endpoint, …).
Trusted for client authenticationbooleanTrust this CA for client authentication, e.g. X.509 client login or the EST protocol.
Exposed on Registration AuthoritybooleanDisplay the CA in the Trust chains view on the RA side
Downloadable on Registration AuthoritybooleanAllow user to download the CA from the Trust chains view on the RA side.

Frequently Asked Questions

On this page