Horizon 2.10.0 release notes
Here are the release notes for EverTrust Horizon v2.10.0, released on 2026-06-16.
For the installation and upgrade procedure, please refer to the Installation and Upgrade guide.
| Tink AWS now uses AWS SDK v2 credentials config. If you used AWS for the tink keyset, your credentials might need to be updated. |
| WebRA third party scheduled tasks renew capability has been removed. Migrate to enabling auto renewal for renewal workflows. |
1. New Features
-
DCV Module: Horizon can now automate the Domain Control Validation lifecycle for public certificates. Learn more …
-
Certificates can now be automatically renewed through centralized issuance on the WebRA module. Learn more …
-
Asynchronous certificate lifecycle APIs are now supported for asynchronous PKI connectors. Learn more …
-
Workloads and services can now authenticate to Horizon using a service account based on JWKS scheme. Learn more …
-
Announcements can now be defined and displayed in the Web UI for maintenance schedules or major incidents. Learn more …
-
When renewing public PKI certificates, if the order is still valid on the underlying PKI, Horizon will now reissue a certificate on the same order. Learn more …
-
Certificate enrollment workflows can now require Terms of Service acceptance. Learn more …
-
The X509 authentication identifier can now be configured to produce custom identifiers. Learn more …
-
Datasources can now be defined as mandatory on a certificate profile, stopping enrollment requests when the data source mapping returns no result. Learn more …
-
Horizon now supports dynamic storage backends for archives and reports. Learn more …
-
Client Authentication CAs can now be exported to be used for reverse proxy certificate selection. Learn more …