Create a GoDaddy certificate authority¶
GoDaddy provides a service that streamlines the procurement and management of SSL/TLS certificates. CyberArk has partnered with GoDaddy to give you the ability to quickly and easily request and renew certificates.
Before you begin¶
You're going to need a few things to complete this procedure.
- GoDaddy account
-
GoDaddy ShopperID
Note
GoDaddy shows your ShopperID as Customer # in the developer portal. Both terms refer to the same account identifier.
-
GoDaddy API Key
- GoDaddy API Secret key
For more information, refer to GoDaddy API Access, Usage, and Limitations
- Sign in to Certificate Manager - SaaS.
-
Click Integrations > Certificate Authorities.
-
Click New > Add Certificate Authority connector.
- Enter the Name.
- In the Certificate Authority Type dropdown, select GoDaddy.
- Click Next.
-
In API base URL, enter the GoDaddy API endpoint.
Note
For production, enter
api.godaddy.com. To connect to GoDaddy's OTE test environment instead, enterapi.ote-godaddy.com. -
(Optional) Enter a Renewal Window (days).
The renewal window determines how Certificate Manager - SaaS replaces a GoDaddy certificate. A certificate expiring within the window is renewed; a certificate with more remaining life is reissued, which keeps the original GoDaddy order and expiration date. Learn more about certificate renewal and reissuance.
The default is 32 days. You can enter any value from 1 to 90.
-
Enter the ShopperID.
Note
GoDaddy shows your ShopperID as Customer # in the developer portal. Both terms refer to the same account identifier.
-
Enter the API Key.
-
Enter the API Secret.
Note
The ShopperID, API Key, and API Secret authenticate requests to GoDaddy. Together, they identify your GoDaddy account and determine which certificate products and actions are available through the API.
-
Click Test Access, then click Next.
-
(Optional) In Product Options (issuance), select the certificate authority products to map to request policies.
The GoDaddy connector offers the following products:
Certificate Type Description DV_SSLDomain Validated SSL DV_WILDCARD_SSLDomain Validated Wildcard SSL EV_SSLExtended Validated SSL OV_SSLOrganization Validated SSL OV_WILDCARD_SSLOrganization Validated Wildcard SSL UCC_DV_SSLUCC/SAN Domain Validated SSL UCC_OV_SSLUCC/SAN Organization Validated SSL UCC_EV_SSLUCC/SAN Extended Validated SSL OV_CODE_SIGNINGOrganization Validated Code Signing OV_DRIVER_SIGNINGOrganization Validated Driver Signing Certificate Note
Only the UCC/SAN products support changing subject alternative names (SANs) during reissuance. Learn more.
- (Optional) Click Add to map additional products.
- Click Next.
- (Optional) On the next Product Options page (import), select the certificate authority products to import certificates from.
- Click Add to include additional products.
- (Optional) Enable one or more Import options:
- Include Revoked Certificates
- Include Expired Certificates
- (Optional) Enable Scheduled import.
- Click Create.
What's next¶
This CA is now ready to be added to one or more request policies. To do this, select this CA when creating request policies.