Certification Authorities
Configure the trust store of your CLM environment.
The Certification Authorities settings define the trust store of the CLM application. This is where you register every CA that Horizon needs to know about, and where you declare what each CA is trusted for.
A single CA entry can play one or more of the following roles:
- Trust chain material — CA certificates that may need to be included in the certificate bundle downloaded by an end user, so the issued certificate validates against a complete chain.
- Server authentication trust — CAs that must be trusted when Horizon reaches an external system over TLS (datasources, an F5 load balancer, REST endpoints, LDAP servers, etc.).
- Client authentication trust — CAs that must be trusted when a client presents a certificate to Horizon, for instance X.509 client authentication for local login, or the EST protocol.
Trust chains can additionally be exposed on the Registration Authority (RA), allowing end users to download the chain directly from the RA interface.
By default, the system trusts valid certificate chains issued by public CAs for server authentication. You may still need to add the full chain if you require complete trust chain material for certificate bundles, or need it for client authentication trust.
Prerequisites
You will need each Certification Authority beforehand, in one of these formats:
- a certificate file (PEM or DER) or a certificate string (PEM).
- its revocation endpoint URL (DER, HTTP only)
How to configure a Certification Authority
- In Horizon, go to Certificate Authorities.
- Click the Add (
+) button.
The wizard walks through three tabs: Certificate → Details → Configuration.
Certificate tab
Provide the CA certificate, either by:
- pasting the certificate string (PEM), or
- importing the certificate file (PEM or DER).
Then click Next.
Details tab
Review the information parsed from your CA certificate (subject, issuer, validity, key usage, etc.) to confirm you imported the right CA. Then click Next.
Configuration tab
Fill in the settings below, then click Import.
| Field | Type | Description |
|---|---|---|
| Name (required) | string | A meaningful, unique name for the Certification Authority. |
| OCSP responder URL (optional) | string | URL of the OCSP responder, if available. |
| CRL URL (optional) | string | URL to download the CRL (HTTP). |
| Outdated Revocation Status Policy (required) | select | Behavior when the CRL/OCSP cannot be reached and revocation data is stale. For production environments, "Revoked" is recommended. |
| Refresh Period | finite duration | How often the CRL or OCSP status is refreshed. Must be a valid finite duration. Recommended value: between 1h and 24h. |
| Proxy | select | The HTTP/HTTPS proxy used to reach the CRL or OCSP responder, if one is required. |
| Timeout | finite duration | Connection timeout when reaching the CRL or OCSP endpoint. Must be a valid finite duration. |
| Trusted for server authentication | boolean | Trust this CA for SSL/TLS server trust, i.e. when CLM connects out to an external system (datasource, F5 load balancer, REST endpoint, …). |
| Trusted for client authentication | boolean | Trust this CA for client authentication, e.g. X.509 client login or the EST protocol. |
| Exposed on Registration Authority | boolean | Display the CA in the Trust chains view on the RA side |
| Downloadable on Registration Authority | boolean | Allow user to download the CA from the Trust chains view on the RA side. |