LogoSwissSign CLM
Protocols

Enrollment Protocols

Overview of the certificate enrollment protocols supported by Horizon

Horizon supports several certificate enrollment protocols. Each was designed for a different class of system, and most organisations use two or three simultaneously. The same Horizon profile can have multiple protocols enabled.

If you are deciding which protocol to use, start with Choose the right protocol — it walks through the decision in order of preference, starting with the Horizon Agent.

Protocols

ACME

Automatic Certificate Management Environment (RFC 8555). Used by applications and appliances with a built-in ACME client — Caddy, Traefik, Proxmox VE, Synology DSM, and Cisco ASA/FTD among others. Horizon exposes an RFC 8555-compliant directory endpoint compatible with any standard ACME client.

EST

Enrollment over Secure Transport (RFC 7030). The protocol used by the Horizon Agent (horizon-cli) for server and workstation enrollment. EST authenticates devices using a challenge password at first enrollment, then mutual TLS for all subsequent renewals. Preferred over SCEP wherever both are available.

SCEP

Simple Certificate Enrollment Protocol (RFC 8894). The most widely supported enrollment protocol in network equipment. Used for firewalls, switches, routers, VPN gateways, and MDM platforms such as Microsoft Intune and Jamf Pro that request certificates on behalf of managed devices.

WSTEP / WCCE

The certificate enrollment protocols built into Windows. Domain-joined machines and users enroll via Group Policy auto-enrollment using Kerberos authentication — no additional software required. Horizon presents the same interface as ADCS, so no Group Policy changes are needed beyond updating the enrollment endpoint URL.

On this page