Horizon-cli 1.18.0 release notes

Here are the release notes for EverTrust Horizon Client v1.18.0, released on 2026-08-07. For the installation and upgrade procedure, please refer to the Installation and Upgrade guide.

Horizon Client is now also distributed as a Debian (.deb) package. Learn more …​

1. New Features

  • Service account authentication is now available. Learn more …​

  • WebRA asynchronous enrollments and renewals are now supported across the WebRA and automate modules

  • Netimport now supports Sectigo. The new netimport sectigo command discovers issued SSL certificates from a Sectigo Certificate Manager (SCM) account and imports them into a Horizon discovery campaign. Learn more …​

  • Localscan: whole folders can now be excluded from a scan by passing a directory path to the existing --exclude-files option

2. Enhancements

  • DigiCert netimport: the DigiCert CertCentral API endpoint can now be set manually with the --api-url flag.

  • GlobalSign netimport: the GlobalSign API endpoint can now be set manually with the --api-url flag. The --test flag is now deprecated in favor of --api-url and will be removed in a future release.

3. Bug Fixes

  • Fixed an issue where the certificate chain order was incorrectly reset after renewal. This affected certificates managed prior to version 1.14.0 as well as certificates controlled with the automate control command between versions 1.14.0 and 1.17.1.

    This fix uses the current state of the chain on the file system to determine the expected chain order. If the chain order on the file system is already incorrect, the fix will not work as expected.
  • Fixed an issue where --ou was ignored when it was the only DN flag provided in automate commands.

  • Fixed an issue where the EST enrollment could panic when an HTTP error without Content-Type header was returned

  • Fixed an issue where the --dn option was not transmitted to the challenge request when using the --request-challenge option in the automation module

  • Fixed an issue where .pfx files were not imported when using localimport

  • Fixed an issue where a decentralized WebRA enrollment failed with unable to parse private key PEM when the request was completed asynchronously by automate routine after approval

  • Fixed an issue where DigiCert netimport failed to use the configured proxy when downloading certificates

4. Reworked features

[None]

5. Known Defects

[None]