LogoSwissSign CLM
Protocols

ACME

Automatic Certificate Management Environment — how it works and where it fits

ACME (RFC 8555) is the protocol behind Let's Encrypt. It lets a client prove it controls a domain or identifier and receive a certificate entirely without human interaction. Horizon exposes an ACME directory endpoint so any RFC 8555-compatible client can use SwissSign or your internal CA as the issuer.

How it works

  1. The client contacts the Horizon ACME directory and creates an account (or reuses an existing one).
  2. Horizon issues a challenge: prove you control the identifier in the certificate request.
  3. The client completes the challenge (HTTP-01, DNS-01, or TLS-ALPN-01).
  4. Horizon verifies the challenge, issues the certificate, and returns it to the client.
  5. The client stores the certificate and schedules automatic renewal — typically at 60–80% of the validity period.

Challenge types

ChallengeHow the client proves controlWhen to use
HTTP-01Serves a token at http://<domain>/.well-known/acme-challenge/Public web servers with port 80 accessible from Horizon
DNS-01Creates a TXT record at _acme-challenge.<domain>Wildcard certificates; servers not reachable from Horizon
TLS-ALPN-01Responds to a TLS handshake on port 443 with a special certificateEnvironments where only port 443 is open

Wildcard certificates (*.example.com) can only be issued using DNS-01. HTTP-01 and TLS-ALPN-01 cannot validate wildcard identifiers — this is an RFC 8555 constraint, not a Horizon limitation.

Choosing a challenge type: EverTrust's guidance is to prefer DNS-01 when the system requesting the certificate is not the asset being secured (for example, a pipeline requesting on behalf of a server). When the asset makes its own request and is reachable from Horizon, prefer HTTP-01. Use TLS-ALPN-01 only when neither HTTP-01 nor DNS-01 is viable.

For HTTP-01 and TLS-ALPN-01, Horizon initiates a connection back to the asset to verify the challenge. If Horizon cannot reach the asset directly — for example because it sits in a DMZ — you can configure an HTTP proxy on the ACME profile to relay validation requests. Horizon retries verification up to 3 times with a 3-second delay between attempts by default; both values are configurable on the profile.

Where ACME fits

  • Applications with a native ACME client — Caddy, Traefik, and similar tools that manage TLS internally. Configuring them to point at Horizon's ACME directory is simpler than deploying a separate enrollment agent.
  • Appliances with no other automated enrollment path — some systems such as Proxmox VE, Synology DSM, and Cisco ASA/FTD have built-in ACME clients but no dedicated Horizon connector. See Choose the right protocol for the full list.
  • CI/CD pipelines — ACME clients are available as scriptable CLI tools for any environment.

Where ACME does not fit

  • Internal hostnames and IP addresses — HTTP-01 and DNS-01 require publicly resolvable names or split-horizon DNS. For internal workloads, use the Horizon Agent (EST) instead.
  • Network devices that support EST or SCEP — ACME's domain validation model is not well suited to device identity certificates. Use EST or SCEP for firewalls, switches, and similar gear.
  • Any server where the Horizon Agent can run — the Agent is always preferred over a raw ACME integration for general-purpose servers. See Choose the right protocol.

Revocation

Revocation is a supported ACME lifecycle operation. Clients can revoke a certificate directly through the ACME endpoint without going through the Horizon web interface or API. The standard ACME revocation flow applies: the client authenticates with its account key and submits the certificate to revoke.

Qualified ACME clients

EverTrust maintains a list of clients tested against Horizon in continuous integration. Other RFC 8555-compliant clients will generally work but are not covered by qualification testing.

PlatformQualified clients
Linuxacme.sh, Certbot, Lego, horizon-cli
WindowsLego, WinCertes, horizon-cli
Kubernetescert-manager

WinCertes is open source and maintained by EverTrust. It supports automatic IIS binding, Windows Scheduled Task creation for renewal, and post-renewal PowerShell scripts.

ACME endpoint URL

The Horizon ACME directory endpoint follows this pattern:

https://<horizon-host>/acme/<profile-name>/directory

Point your ACME client's server setting at this URL. Each ACME profile has its own directory endpoint, so different profiles can enforce different issuance policies for different client populations.

External Account Binding (EAB)

Horizon can require EAB credentials before an ACME account is created. This ties each ACME client to a known identity and prevents anonymous certificate issuance. EAB is strongly recommended for all internal ACME deployments.

Configuring ACME in Horizon

ACME is enabled per-profile. Refer to the Horizon ACME connector documentation for setup steps.

On this page