Add GoDaddy
Table of Contents
Expand all | Collapse all
-
- Activate Next-Generation Trust Security
-
-
- Configure Akamai Connection
- Configure AWS Connection
- Configure Azure Key Vault Connection
-
- Workload Identity Federation Authentication
- Workload Identity Federation - Azure Identity Provider Authentication
- Next-Gen Trust Security Generated Key Authentication
- User Permissions
- Workload Identity Federation Authentication
- Next-Gen Trust Security Generated Key Authentication
- User Permissions
- Supported OIDC Claims
-
-
-
- Working with the Built-in CA
- Add AWS Public CA
- Add AWS Private CA
- Add DigiCert One Certificate Authority
- Add Entrust
- Add GlobalSign Atlas
- Add GlobalSign MSSL
- Add GoDaddy
- Add Google Cloud Private CA
- Add a HID PKIaaS CA
- Add Certificate Manager - Self-Hosted
- Set Up an OpenSSL Certificate Authority Connector
- Create a Sectigo Certificate Manager Certificate Authority
- Add SSL.com
- Add Zero Touch PKI
- Set Up Certificate Expiration Notifications
- Using a Custom DNS Provider
- CNAME Delegation for Domain Validation
- About Authorized Domains
-
-
-
-
- Create an F5 BIG-IP LTM Machine
- Create a Microsoft Azure Private Key Vault Machine
- Create a Microsoft Azure Application Registration Machine
- Create a Microsoft IIS Machine
- Create a Microsoft Windows (PowerShell) Machine
- Create a Microsoft SQL Server Machine
- Create a Common KeyStore Machine
- Create a Citrix ADC Machine
- Create an Imperva WAF Machine
- Create a VMware NSX Advanced Load Balancer (AVI) Machine
- Create an A10 Thunder ADC Machine
- Create a Cloudflare Machine
- Create Kemp Virtual LoadMaster Machine
- Create a Palo Alto Networks Panorama Machine
- Create a Radware Alteon Machine
- Create an Amazon Secrets Manager Machine
- Create a Microsoft Azure Application Gateway Machine
- Create a Microsoft Azure API Management Machine
- Create an F5 Distributed Cloud Machine
- Create a Fortinet FortiGate Machine
- Create an IBM DataPower Gateway Machine
- Create a Google Cloud Classic Load Balancer Machine
-
- Provision to an F5 BIG-IP LTM
- Provision to a Microsoft Azure Private Key Vault
- Provision to Microsoft IIS
- Provision to Microsoft Windows (PowerShell)
- Provision to Microsoft SQL Server
- Provision to a Common KeyStore
- Provision to a Citrix ADC
- Provision to an Imperva WAF
- Provision to VMware NSX Advanced Load Balancer (AVI)
- Provision to an A10 Thunder ADC
- Provision to Cloudflare
- Provision to a Kemp Virtual LoadMaster
- Provision to Palo Alto Networks Panorama
- Provision Certificates to Radware Alteon
- Provision to Amazon Secrets Manager
- Provision to a Microsoft Azure Application Gateway
- Provision to Microsoft Azure API Management
- Provision to F5 Distributed Cloud
- Provision to a Fortinet FortiGate
- Provision to an IBM DataPower Gateway
- Provision to a Google Cloud Classic Load Balancer
-
-
- 47-Day Validity Readiness TLS Certificates
- About the Certificate Inventory
- Managing Certificate Lifecycle Settings
- Reissuing Certificates in Next-Gen Trust Security
- Downloading Certificates, Certificate Chains, and Keystores
- Retiring, Recovering, and Deleting Certificates
- Finding Certificates in the Certificate Inventory
- Importing Certificates from DigiCert
- Importing Certificates from EJBCA
- Importing Certificates from GlobalSign Atlas
- Importing Certificates from GlobalSign MSSL
-
- Create a Workload Identity Management or Discovery Agent Built-in Account
- Create an OCI Registry Built-in Account
- Create a Certificate Manager - Self-Hosted Built-in Account
- Create a Scanafi Built-in Account
- Toggling a Built-in Account On or Off
- Editing Built-in Accounts
- Deleting Existing Built-in Accounts
- Renew Existing Built-in Accounts
- Licensing PKI
- Troubleshooting
Add GoDaddy
GoDaddy provides a service that streamlines the procurement and management of SSL/TLS certificates.CyberArk has partnered with GoDaddy to give you the ability to quickly and easily request and renew certificates.
Before You Begin
You're going to need a few things to complete this procedure.
- GoDaddy account
- GoDaddy ShopperIDNote: GoDaddy shows your ShopperID as Customer # in the developer portal. Both terms refer to the same account identifier.
- GoDaddy API Key
- GoDaddy API Secret key
For more information, refer to GoDaddy API Access, Usage, and Limitations
- Sign in to Next-Gen Trust Security.
- Click Configuration > Certificate Integrations > Certificate Authorities.
- Click New > Add Certificate Authority connector.
- Enter the Name.
- In the Certificate Authority Type dropdown, select GoDaddy.
- Click Next.
- In API base URL, enter the GoDaddy API endpoint.Note: For production, enter api.godaddy.com. To connect to GoDaddy's OTE test environment instead, enter api.ote-godaddy.com.
- (Optional) Enter a Renewal Window (days).The renewal window determines how Next-Gen Trust Security replaces a GoDaddy certificate. A certificate expiring within the window is renewed; a certificate with more remaining life is reissued, which keeps the original GoDaddy order and expiration date. Learn more about certificate renewal and reissuance.The default is 32 days. You can enter any value from 1 to 90.
- Enter the ShopperID.Note: GoDaddy shows your ShopperID as Customer # in the developer portal. Both terms refer to the same account identifier.
- Enter the API Key.
- Enter the API Secret.Note: The ShopperID, API Key, and API Secret authenticate requests to GoDaddy. Together, they identify your GoDaddy account and determine which certificate products and actions are available through the API.
- Click Test Access, then click Next.
- (Optional) In Product Options (issuance), select the certificate authority products to map to request policies.The GoDaddy connector offers the following products:
Certificate Type Description DV_SSL Domain Validated SSL DV_WILDCARD_SSL Domain Validated Wildcard SSL EV_SSL Extended Validated SSL OV_SSL Organization Validated SSL OV_WILDCARD_SSL Organization Validated Wildcard SSL UCC_DV_SSL UCC/SAN Domain Validated SSL UCC_OV_SSL UCC/SAN Organization Validated SSL UCC_EV_SSL UCC/SAN Extended Validated SSL OV_CODE_SIGNING Organization Validated Code Signing OV_DRIVER_SIGNING Organization Validated Driver Signing Certificate Note: Only the UCC/SAN products support changing subject alternative names (SANs) during reissuance. Learn more.- (Optional) Click Add to map additional products.
- Click Next.
- (Optional) On the next Product Options page (import), select the certificate authority products to import certificates from.
- Click Add to include additional products.
- (Optional) Enable one or more Import options:
- Include Revoked Certificates
- Include Expired Certificates
- (Optional) Enable Scheduled import.
- Click Create.
What's Next
This CA is now ready to be added to one or more request policies. To do this, select this CA when creating request policies.