Horizon 2.11.0 release notes
Here are the release notes for EverTrust Horizon v2.11.0, released on 2026-10-01.
For the installation and upgrade procedure, please refer to the Installation and Upgrade guide.
| The LDAP connector now verifies that the server certificate matches the configured hostname. Connections to an LDAP server whose certificate does not match this hostname will fail after the upgrade; enable TLS Insecure on the connector to bypass this check. |
The AWS connector now sends evt-<uuid>
instead of EverTrustHorizon-Session-<uuid> as the roleSessionName of its AssumeRole requests. If your IAM
policies match on the session name, update them before upgrading.
|
OCSP response verification now enforces the id-kp-OCSPSigning extended key usage for delegated OCSP responder certificates.
|
| The F5 connector now names the CA chains it pushes after the connector prefix. On the first push after the upgrade, CA chains are pushed under their new name and the client SSL profiles managed by Horizon are bound to them. CA chains pushed by earlier versions are left in place; SSL profiles bound to them outside of Horizon are not updated. |
1. New Features
-
ACME: Added support for External Account Bindings and IP identifiers, as well as account and orders management capabilities
-
Google Cloud Certificate Authority Service (CAS) is now supported as a PKI connector. Learn more …
-
Certificates can now be deployed to Fortinet FortiGate firewalls and FortiManager appliances. Learn more …
-
Certificates can now be deployed to Palo Alto PAN-OS firewalls, either standalone or managed through Panorama. Learn more …
-
GlobalSign MSSL is now supported as a DCV provider, automating domain control validation for certificates issued through the GlobalSign MSSL PKI connector. Learn more …
-
Sectigo is now supported as a DCV provider, automating domain control validation for certificates issued through the Sectigo PKI connector. Learn more …
-
WebRA profiles can now authorize enrollments with a one-time challenge, as SCEP and EST profiles do. Learn more …
-
EST profiles in
Authorizedmode now accept client certificate authentication on thesimpleenrollendpoint. -
Service accounts can now present their JWT in the standard
Authorization: Bearerheader. Learn more … -
Custom dashboards can now be exported to and imported from JSON files, to share them between users. Learn more …
2. Enhancements
-
Renewals now reuse the initial enrollment request instead of the issued certificate, so certificates modified by the CA at issuance are renewed as originally requested
-
F5 connector: the configuration can now be saved to
bigip.confafter each deployment, and pushed CA chains are now named after the connector prefix. Learn more … -
ACME: profiles now provide an option to exclude the root CA from the returned certificate chain
-
OIDC identity providers: claims mapping can now synchronize roles only, teams only, or both. Learn more …
-
Updating, renewing or migrating a certificate now only submits the modified fields, so concurrent edits no longer overwrite each other and unchanged submissions no longer create a request
-
OCSP response verification now fully enforces Extended Key Usages requirements.