Horizon 2.10.0 release notes
Here are the release notes for EverTrust Horizon v2.10.0, released on 2026-06-16.
For the installation and upgrade procedure, please refer to the Installation and Upgrade guide.
The rpm and deb packages no longer bundle or automatically install a Java runtime. Horizon now supports both Java 17 and Java 21, so you must install one of them on the host
before installing or upgrading.
|
| Tink AWS now uses AWS SDK v2 credentials config. If you used AWS for the tink keyset, your credentials might need to be updated. |
| WebRA third party scheduled tasks renew capability has been removed. Migrate to enabling auto renewal for renewal workflows. |
1. New Features
-
DCV Module: Horizon can now automate the Domain Control Validation lifecycle for public certificates. Learn more …
-
Certificates can now be automatically renewed through centralized issuance on the WebRA module. Learn more …
-
Asynchronous certificate lifecycle APIs are now supported for asynchronous PKI connectors. Learn more …
-
Workloads and services can now authenticate to Horizon using a service account based on JWKS scheme. Learn more …
-
Announcements can now be defined and displayed in the Web UI for maintenance schedules or major incidents. Learn more …
-
When renewing public PKI certificates, if the order is still valid on the underlying PKI, Horizon will now reissue a certificate on the same order. Learn more …
-
Certificate enrollment workflows can now require Terms of Service acceptance. Learn more …
-
The X509 authentication identifier can now be configured to produce custom identifiers. Learn more …
-
Datasources can now be defined as mandatory on a certificate profile, stopping enrollment requests when the data source mapping returns no result. Learn more …
-
Horizon now supports dynamic storage backends for archives and reports. Learn more …
-
Client Authentication CAs can now be exported to be used for reverse proxy certificate selection. Learn more …
4. Known Defects
-
In rare cases, a new event can be inserted without the required synchronization data, which prevents the event analytics database from synchronizing and thus responding to any further requests. This issue has been resolved in
2.10.2 -
Certificate revocation through the DigiCert connector fails to complete. This issue has been resolved in
2.10.3 -
Enrollment requests through the Sectigo connector fail to complete. This issue has been resolved in
2.10.4 -
Stream connector does not forward the value of the MS Template V2 extension. This issue has been resolved in
2.10.6 -
Stream connector fails to enroll when using certificate authentication. This issue has been resolved in
2.10.6 -
Stream connector fails to enroll when using WCCE Escrow mode. This issue has been resolved in
2.10.6 -
OTPKI connector does not set values for the RFC822Name (email) SAN, resulting in certificates where this field is missing. This issue has been resolved in
2.10.6