Horizon-cli 1.16.0 release notes
Here are the release notes for EverTrust Horizon Client v1.16.0, released on 2026-04-13. For the installation and upgrade procedure, please refer to the Installation and Upgrade guide.
1. New Features
-
[HOR-923]- All enrollment commands now support a--dnflag to specify the full Subject DN, enabling use of additional DN attributes such as DC. -
[HOR-939]- Ensured Windows Server 2025 support. -
[HOR-970]- Panorama discovery is now supported in thenetimportsection. -
[HOR-972]- Tenable.sc is now supported as a scan import source in theimportscansection. -
[HOR-996]- A new--updateflag is now available for protocol enrollment commands, allowing JKS and KDB keystores to be updated in place rather than overridden. -
[HOR-1019]- A newHRZ_LOCALDBenvironment variable is now supported to configure an alternative configuration directory. -
[HOR-1021]- A newhorizon-cli automate editcommand is now available to modify certificate options in the client internal state. -
[HOR-809]- A new--generic-windows-archivalflag is now available onhorizon-cli installto control whether outdated certificates are removed from the Windows store after renewal. This is to ensure compatibility with pre 1.11 versions.
2. Enhancements
-
[HOR-1024]-horizon-cli automate listnow displays certificates deleted outside the CLI as "Could not retrieve" instead of failing, andhorizon-cli automate removenow supports removing such entries from state. -
[HOR-1140]- TLS ciphers reported by the NMAPssl-enum-ciphersscript are now parsed and displayed in Horizon scan results. -
[HOR-754]- IP SANs are now displayed alongside DNS SANs inhorizon-cli automate listoutput. -
[HOR-78]- The--scan-tlsflag is now available innetscanto test all TLS versions supported by an endpoint.
3. Bug Fixes
-
[HOR-882]- Fixed an issue where EC certificates were not retrieved during an F5 netimport. -
[HOR-1017]- Fixed an issue wherehorizon-cli webra enrollreturned unclear error messages when using a non-existent profile or a profile with a manual password policy.
5. Known Defects
-
Defects in the chain order feature cause the chain to reset to root-to-leaf order after renewal. This may have a significant operational impact. This affects:
-
Certificates under management prior to version 1.14.0
-
Certificates controlled with the
automate controlcommand. Fixed in version1.17.1
The issue is currently being addressed, and a fixed version will be available soon.
-
-
The
--ouoption in theautomatemodule is ignored when used on its own, without an accompanying--cor--ooption. The issue is currently being addressed, and a fixed version will be available soon.