Horizon-cli 1.17.0 release notes

Here are the release notes for EverTrust Horizon Client v1.17.0, released on 2026-06-19. For the installation and upgrade procedure, please refer to the Installation and Upgrade guide.

1. New Features

  • The netimport akv and netimport aws-acm commands now expose a --connector flag to attach the corresponding third-party connector metadata to discovered certificates, enabling renewals to update the existing AKV or ACM object instead of creating a new one

  • ACME automation commands using DNS-01 challenges can now bypass the client-side authoritative name server propagation pre-check and tune the DNS-01 operation timing through the --dns-01-propagation-wait and --dns-01-timeout flags

  • Automation commands can now set a dedicated password on the JKS alias entry using the --jks-alias-pwd option

2. Enhancements

[None]

3. Bug Fixes

  • Automation: Removed an erroneous backup log emitted during new enrollments on generic targets

  • Localimport: Fixed an issue where certificates encoded as DER Hex strings could not be imported from CSV files

4. Reworked features

[None]

5. Known Defects

  • Defects in the chain order feature cause the chain to reset to root-to-leaf order after renewal. This may have a significant operational impact. This affects:

    • Certificates under management prior to version 1.14.0

    • Certificates controlled with the automate control command. Fixed in version 1.17.1

    The issue is currently being addressed, and a fixed version will be available soon.

  • The --ou option in the automate module is ignored when used on its own, without an accompanying --c or --o option. The issue is currently being addressed, and a fixed version will be available soon.