FAQ – Frequently Asked Questions
I am not receiving my login link
The link is valid for 24 hours and can only be used once. When it does not arrive, it is almost always your mail system holding it — in this order:
1. Check your spam folder. Even with careful sending practices, an automated message can land there. Mark the sender as safe and the next ones will reach your inbox.
2. Add [email protected] to your contacts.
Your mail system relies on your address book to recognise a legitimate
sender — and that is the one the link is sent from.
3. If your mail system asks the sender to confirm — a challenge-response spam filter such as Mailinblack: your message waits in quarantine until we answer. The link stays valid for 24 hours, so it will reach you. To speed up that recognition, send a message first — an empty one will do — to [email protected], the very address the link comes from. Most of these systems automatically allow an address you have written to, so the link will then come straight through. No reply from us is needed: your own message is what lifts the block.
Why did Certeasy change its name to Hortval?
The former name turned out to be shared by other, unrelated products. Same product, same team, same company, and nothing changes for a running deployment. Read the full story.
Is Hortval a certificate authority (CA)?
No. Hortval is not a CA and does not issue public certificates. It acts as an internal ACME server in front of your existing Microsoft ADCS CA. All issuance remains on-prem.
Do I need to expose Hortval on the Internet?
Never. Hortval is designed to run fully on-premise.
Your ACME clients point to an internal URL such as:
https://acme.your-domain.local/directory.
How is Hortval installed?
You install Hortval on an internal server, connect it to your ADCS CA, and configure your servers to use the internal ACME URL.
Does Hortval require Internet access?
Not for its PKI work, and it can run fully air-gapped.
Certificates, private keys, CSRs, the domain names you issue for, ACME data,
DNS configuration and the audit log never leave your network.
By default (connected mode), Hortval makes a single outbound
connection: HTTPS to api.hortval.com for the license lifecycle (registration,
validation, automatic renewal, plan changes). Two categories are sent, and
nothing else.
What describes your installation: the Hortval server's hostname,
the number of managed servers, the number of managed CAs, and the database type.
Plus the environment you declare, at registration only.
What identifies the licence: the licence key, the installation
key, the plan being run, and the binary version. None of these say anything about
your network.
Never: your client hostnames, your certificates, your CSRs, your keys, the domain
names you issue for, your ACME data, your DNS configuration, your audit log. No
analytics, no usage tracking. The exhaustive list is in our
terms of use.
For air-gapped or strictly segmented networks, set isolated mode
(license: offline: true): zero outbound connections.
There is nothing to send either: you quote an installation number, that is all,
and no identifier from your infrastructure leaves your perimeter.
The trade-off is real: the entire licence lifecycle becomes manual.
Renewal, change of offer, retirement, updates: each one means downloading the file
from the portal and installing it on the server. Expiry reminders still arrive by
email, but acting on them is up to you. Isolated mode is a date in a calendar, not
just a line in a configuration file.
A self-update mechanism is planned, and it is a regulatory
requirement of the European market: the Cyber Resilience Act asks
vendors to provide a channel for automatic security updates, together with a
simple way to turn it off.
We will recommend using that second part on this server, for a precise reason:
it holds enrolment rights on your certificate authority. A binary
that replaced itself there without your approval would be a way into your
PKI, and it would bypass your own patch governance. It will exist for the
estates that want it.
What we do instead: the server tells you a new version is available, in its
logs and on the portal. Artefacts are signed, Authenticode on Windows, and
the upgrade goes through the channels you already use. A fix asks for a
restart; a feature release, a maintenance window. Air-gapped or isolated
deployments never update themselves.
What happens if I stop using Hortval?
Nothing immediately. Hortval is not a certificate authority: your ADCS is what issues, with your templates and your policies. Certificates already delivered stay valid until expiry. You lose automatic renewal, not your certificates, and you simply fall back to your previous manual process.
What happens when my licence expires?
You are warned 30 days ahead, by email and in the server logs, with reminders
getting closer together and an announced stop date. Expiry then opens
21 days of margin during which the service keeps running
normally: 7 days automatically, then two 7-day extensions you open with
hortval license force-grace --confirm. Beyond that, only installing
an up-to-date licence brings the service back.
In every case, no certificate already issued is invalidated: the
authority is your ADCS. The full breakdown is in the
documentation.
What does Hortval send to the publisher?
In connected mode, two categories. What describes your installation:
the Hortval server's hostname, the number of managed servers, the number of managed
CAs and the database type, plus the environment you declare at registration only.
What identifies the licence: the licence key, the installation key,
the plan being run and the binary version.
Never your certificates, your keys, your CSRs, the domain names you issue for, or
your client hostnames. No analytics, no usage tracking. In isolated
mode there is nothing to send at all: you quote an installation number,
and no identifier from your infrastructure leaves your perimeter.
How long is my version supported, and how often must I upgrade?
Your ACME clients never change. The interface between them
and Hortval is RFC 8555, not our API: certbot, acme.sh, lego, Caddy and
Traefik are unaffected by any Hortval version. An upgrade touches the server,
never the fleet that talks to it.
From 1.0.0 onward, no release asks you to edit your
configuration. The schema does keep evolving, but that is not a
break: nothing you wrote stops working, and none of your clients is
reconfigured. Additive changes apply on restart; heavier ones wait for
hortval migrate, which is to say for a moment when you are present
and holding a backup. That is not a constraint we impose: it is the moment you
would have chosen, and the gate exists so a restart nobody decided cannot pick
it for you.
Each minor is supported for twelve months. If we do introduce a
breaking change, the fix is backported to the minors still inside their twelve
months: the backport is the price of our own break, not a service you have to
ask for.
Until then, the 0.9.x series still asks you to edit your configuration, and
it is worth naming what that means: the fourteen breaking changes in v0.9.4 and
v0.9.5 are all of them configuration. None touches the ACME
protocol, none touches the schema, none invalidates a certificate. Most are
refused at startup, with the line to write printed for you. So what stops at
1.0.0 is not "breaking your system" but "asking you to edit your configuration
again".
Full detail in the documentation.
Is Hortval production-ready?
Hortval is a stable release: it runs in production, it does
not crash, and it issues, renews and revokes every day. Core ACME issuance,
HTTP-01, DNS-01 and TLS-ALPN-01 validation, and revocation (CRL/OCSP
propagation to ADCS) are all implemented and supported, with certbot, acme.sh
and lego.
Stable and production-ready are not the same thing, and we
reserve the second label for two steps that remain. 0.9.6
brings what a Windows deployment still lacks: startup under the Service
Control Manager, a dedicated account, the installer and the event log.
1.0.0 completes it with automatic record retention and the
supervision endpoints.
Concretely, today: v0.9.5 runs in a console or under a third-party supervisor,
not directly from sc.exe. That is written in the changelog rather
than left to be discovered.
Plan limits (managed server quota, CA count) are enforced by the binary at
startup and on every new order, including during the evaluation period.
Are there any known limitations?
Yes, and we list them openly. As of today:
• Data retention: there is no automatic cleanup yet, so ACME
records (orders, authorizations, challenges) accumulate over time. On
long-lived deployments, plan periodic maintenance until automated retention
ships.
• Health / metrics endpoints: there are no built-in HTTP
health or metrics endpoints yet, so supervision relies on logs and database
introspection for now.
Neither blocks core certificate automation, and both are scheduled for the V1 release.
See the changelog for the
full, up-to-date list of known limitations.
Can I use certbot with Hortval?
Yes. Hortval supports any standard ACME client including Certbot, acme.sh, lego, Caddy, Posh-ACME, and others.
Which ACME challenges are supported?
Hortval supports HTTP-01, DNS-01 and TLS-ALPN-01 on all plans, today. Distributed validators for segmented networks are planned for V3.
If Hortval goes down, are my certificates at risk?
No. Certificates already issued keep working regardless. ACME clients start renewal 30 days before expiry, giving ample time to restore the service before any certificate actually expires.
What's the difference between the Free, Starter, Pro and Enterprise plans?
• Free: 1 production installation, ~25 managed servers,
1 ADCS production authority. Renewed annually at €0, price locked.
• Starter: €299/year, 1 production installation,
~250 managed servers, 2 ADCS production authorities.
• Pro: €499/year, 1 production installation
(cold Active/Passive supported), unlimited managed servers,
3 ADCS production authorities, PostgreSQL, SQL Server.
• Enterprise: €999/year/CA, everything in Pro +
up to 5 ADCS production authorities, split deployment,
Active/Active HA (V2), distributed validators (V3).
What does "1 production installation" mean?
One license covers one production Hortval deployment. Dev and staging instances may run under the same license at no additional cost. They do not count as production installations.
Can I run multiple Hortval instances?
Yes. One license covers one production installation, and dev and staging are included. For failover you can run cold Active/Passive (a second host, standby stopped, manual switchover) with PostgreSQL or SQL Server. Warm Active/Passive and Active/Active multi-node deployments are planned for V2 (Enterprise).
How does high availability work?
Today, Hortval runs as a single instance, or as
cold Active/Passive with manual switchover: the standby is
fully stopped, and you fail over by stopping the active node and starting the
standby (shared PostgreSQL or SQL Server, no SQLite). Running two instances
concurrently is not supported.
Warm Active/Passive and Active/Active high availability are
planned for V2 (Enterprise).
Do plan limits apply right now?
Yes. The managed server quota (distinct ACME accounts with at least one active certificate) and CA count limits are enforced according to your plan, including during the evaluation period. You can switch to a different evaluation plan during the trial; the new plan's limits apply from that point.
What happens after the 6-month free trial?
Nothing automatic. 15 days before expiry, we'll ask whether you want to
continue. If you subscribe, you pay for a year. A new license file is sent
to your email. Replace the existing hortval.lic on your server:
no reinstallation, no configuration change. Your license is extended by one
year from the trial expiry date, not from the payment date.
On connected installations, auto-renewal can be configured so the binary
fetches and replaces the file itself. On air-gapped servers, the manual
file replacement is the only step required.
If you stop, the license simply expires.
What does "price stability over time" mean?
Once you become a customer, your price stays the same. Any future pricing changes will apply only to new customers.
What database should I use?
SQLite (Free, Starter): zero setup, single file, sufficient
for most deployments up to ~250 managed servers.
PostgreSQL or SQL Server (Pro+): recommended for larger
infrastructures, cold Active/Passive failover, and teams that already operate
a PostgreSQL or SQL Server stack.
Are the certificates secure?
Yes. Hortval uses your existing ADCS templates and policies. Certificates are identical to those issued through Microsoft consoles, just automatically.
Can we audit the source code before buying?
Yes. Source code access is available under NDA for security evaluation purposes — whether you are a prospect or an existing customer. Contact us at [email protected] to request access.
What features are planned next?
V2: split deployment (ADCS connector on Tier 0),
warm Active/Passive and Active/Active high availability.
V3: distributed validation agents for segmented networks.
V4: admin dashboard, certificate expiry tracking, network discovery.
How does support work?
• Free: email support (best-effort, for now).
• Starter: email support.
• Pro: priority email support.
• Enterprise: priority email and Teams support.
There is no phone support.
Do you offer onboarding or professional services?
Yes. Paid onboarding and advanced-support engagements are available on request, on any plan. A one-year license is included in the engagement, so the license cost for that year is effectively covered by the service. Contact us at [email protected] for a quote.
Can I upgrade from Starter to Pro or Enterprise?
Yes, at any time. Upgrading requires no reinstallation.