GlobalSign MSSL DCV Provider

This section details how to configure a DCV Provider for the legacy GlobalSign Certificate Center (GCC) platform, through its Managed SSL (MSSL) API.

This provider only handles domain control validation. Certificates are still enrolled through the existing GlobalSign MSSL PKI connector.

Prerequisites

  • You need a GlobalSign Certificate Center account with a Managed SSL (MSSL) profile and API access enabled.

  • You need the MSSL profile ID the domains to validate belong to.

  • You need an API user (login and password) allowed to list domains, retrieve their validation codes, verify them and renew them.

Supported validation methods

Horizon validates domains through the DNS-based methods offered by GlobalSign MSSL. Domains vetted by email are not supported.

When a domain is already approved on GlobalSign, Horizon requests a domain renewal on GlobalSign to obtain a new challenge, then publishes and verifies it like for a new domain.

How to configure a GlobalSign MSSL DCV Provider

1. Log in to Horizon Administration Interface.

2. Access DCV Providers from the drawer or card: DCV  Providers.

3. Click on Add Provider.

4. Fill in the mandatory fields.

General

  • Name* (string input):
    Enter a meaningful provider name. It must be unique for each DCV provider. Horizon uses the name to identify the provider.

  • Type* (select):
    Select GlobalSign MSSL.

Configuration

  • Endpoint* (string input):
    Enter the GlobalSign MSSL API endpoint URL (e.g. https://system.globalsign.com/kb/ws/v1/ManagedSSLService).

  • Profile* (string input):
    Enter the GlobalSign MSSL profile ID the domains belong to.

  • Credentials* (select):
    Select Login credentials containing the GlobalSign MSSL API username and password.

  • Default email* (string input):
    Contact email sent to GlobalSign when renewing a domain.

  • Default phone* (string input):
    Contact phone number sent to GlobalSign when renewing a domain.

  • Timeout* (finite duration):
    Maximum time Horizon waits for a response from the GlobalSign MSSL API.

  • Proxy (select):
    The HTTP/HTTPS proxy to use to reach the GlobalSign MSSL API, if any.

5. Click on the save button.

You can edit Edit Provider or delete Delete Provider the GlobalSign MSSL DCV Provider.

You cannot delete a DCV Provider that is referenced by an existing DCV Policy.