---
title: "Halon 4.5: Advanced certificate management"
description: Discover the new certificate management features in Halon 4.5, making email security and encryption simpler and more effective than ever.
---

[News | Halon ](https://halon.io/blog)

# [Halon 4.5: Advanced certificate management](https://halon.io/blog/halon-4-5-gettin-certy-with-it)

 Written by [Erik Lax](https://halon.io/blog/author/erik-lax) | Jan 30, 2018 11:00:00 PM

The main focus in Halon 4.5 release is TLS, hence the name “certy”. Check out the the new features and functions and try them out. Also, the knowledge base is growing with a lot of good how-to’s to help you around.

TLS information has been made accessible in the Halon Platform scripting language, both on the receiving and sending side. Support for X.509 client certificates has been added, allowing you to both verify the sender identity in the SMTP server, as well as identify yourself when sending email through an SMTP client.

Experiment: we configured a busy email system to ask for a client certificate for all inbound connections, and found that approximate 5% of all traffic provides a client identity. Most of the traffic is from Gmail and Office356. We did not collect the percentage of domains, which we leave as an exercise for you.

```
$peercert = GetTLS();
$haspeercert = isset($peercert["peer_cert"]);
stat("peer-cert", ["yes" => $haspeercert, "no" => !$haspeercert]);
```

How to enable this feature and start authenticating clients was documented as [KB article](https://support.halon.io/hc/en-us/articles/360000107889).

Implementation and facilitation of TLS reporting (tlsrpt) has begun. It is a new standard for reporting TLS failures, mainly focused on MTA-STS and DANE.

The `TLSSocket()` class now have a `getpeercert()` function and the ability to specify a client certificate. Now you see why we called it” certy”?

Support for custom SASL authentication mechanism has been added. This allows you to build authentication schemes such as OTP, OAUTHBEARER or CRAM-MD5, but also EXTERNAL to facilitate the client certificate features. The procedure is [documented](https://support.halon.io/hc/en-us/articles/360000104009-Implement-a-custom-authentication-mechanism) in our knowledge base along with two sample implementations.

> Now with custom SASL mechanism support, I did CRAM-MD5, who implements [#OAUTHBEARER](https://twitter.com/hashtag/OAUTHBEARER?src=hash&ref_src=twsrc%5Etfw) or [#OTP](https://twitter.com/hashtag/OTP?src=hash&ref_src=twsrc%5Etfw)? [pic.twitter.com/KoMd0gEJJI](https://t.co/KoMd0gEJJI)
> 
> — Halon.io (@halon_io) [January 8, 2018](https://twitter.com/halon_io/status/950302177674874880?ref_src=twsrc%5Etfw)

If you haven’t found our knowledge base before, the KB is a place to find how-to’s. The dev team is expanding it as fast as we can, adding topics that customers have asked about.

Finally, I want to highlight the big effort we’ve done to simplify, modernize and overall improve the web administration. This is an ongoing project, and something that we’re paying a lot of attention to. We want to thank, and congratulate, the Bootstrap team for providing such a awesome framework. We managed to get the Bootstrap 4.0 release in, with just a few days of work.

You can [read the full changelog on our GitHub](https://github.com/halon/changelog) of all the other features big and small.

[View full post](https://halon.io/blog/halon-4-5-gettin-certy-with-it)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Erik Lax"
  },
  "dateModified" : "2024-12-05T10:21:50.965Z",
  "datePublished" : "2018-01-30T23:00:00Z",
  "headline" : "Halon 4.5 – gettin’ certy with it",
  "image" : {
    "@type" : "ImageObject",
    "height" : 200,
    "url" : "https://2734201.fs1.hubspotusercontent-na1.net/hubfs/2734201/Imported_Blog_Media/release4-5-certy.png",
    "width" : 1000
  },
  "mainEntityOfPage" : "https://halon.io/blog/halon-4-5-gettin-certy-with-it",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Halon blog"
  }
}
```