Skip to content

Create a GoDaddy certificate authority

GoDaddy provides a service that streamlines the procurement and management of SSL/TLS certificates. CyberArk has partnered with GoDaddy to give you the ability to quickly and easily request and renew certificates.

Before you begin

You're going to need a few things to complete this procedure.

  • GoDaddy account
  • GoDaddy ShopperID

    Note

    GoDaddy shows your ShopperID as Customer # in the developer portal. Both terms refer to the same account identifier.

  • GoDaddy API Key

  • GoDaddy API Secret key

For more information, refer to GoDaddy API Access, Usage, and Limitations

  1. Sign in to Certificate Manager - SaaS.
  2. Click Integrations > Certificate Authorities.

  3. Click New > Add Certificate Authority connector.

  4. Enter the Name.
  5. In the Certificate Authority Type dropdown, select GoDaddy.
  6. Click Next.
  7. In API base URL, enter the GoDaddy API endpoint.

    Note

    For production, enter api.godaddy.com. To connect to GoDaddy's OTE test environment instead, enter api.ote-godaddy.com.

  8. (Optional) Enter a Renewal Window (days).

    The renewal window determines how Certificate Manager - SaaS replaces a GoDaddy certificate. A certificate expiring within the window is renewed; a certificate with more remaining life is reissued, which keeps the original GoDaddy order and expiration date. Learn more about certificate renewal and reissuance.

    The default is 32 days. You can enter any value from 1 to 90.

  9. Enter the ShopperID.

    Note

    GoDaddy shows your ShopperID as Customer # in the developer portal. Both terms refer to the same account identifier.

  10. Enter the API Key.

  11. Enter the API Secret.

    Note

    The ShopperID, API Key, and API Secret authenticate requests to GoDaddy. Together, they identify your GoDaddy account and determine which certificate products and actions are available through the API.

  12. Click Test Access, then click Next.

  13. (Optional) In Product Options (issuance), select the certificate authority products to map to request policies.

    The GoDaddy connector offers the following products:

    Certificate Type Description
    DV_SSL Domain Validated SSL
    DV_WILDCARD_SSL Domain Validated Wildcard SSL
    EV_SSL Extended Validated SSL
    OV_SSL Organization Validated SSL
    OV_WILDCARD_SSL Organization Validated Wildcard SSL
    UCC_DV_SSL UCC/SAN Domain Validated SSL
    UCC_OV_SSL UCC/SAN Organization Validated SSL
    UCC_EV_SSL UCC/SAN Extended Validated SSL
    OV_CODE_SIGNING Organization Validated Code Signing
    OV_DRIVER_SIGNING Organization Validated Driver Signing Certificate

    Note

    Only the UCC/SAN products support changing subject alternative names (SANs) during reissuance. Learn more.

    1. (Optional) Click Add to map additional products.
    2. Click Next.
    3. (Optional) On the next Product Options page (import), select the certificate authority products to import certificates from.
    4. Click Add to include additional products.
    5. (Optional) Enable one or more Import options:
    6. Include Revoked Certificates
    7. Include Expired Certificates
    8. (Optional) Enable Scheduled import.
    9. Click Create.

What's next

This CA is now ready to be added to one or more request policies. To do this, select this CA when creating request policies.