Sectigo DCV Provider
This section details how to configure a DCV Provider for Sectigo Certificate Manager (SCM).
| This provider only handles domain control validation. Certificates are still enrolled through the existing Sectigo PKI connector. |
Prerequisites
-
You need a Sectigo Certificate Manager account with REST API access.
-
You need an API client (client ID and client secret) allowed to list the account domains and to manage their domain control validations.
Supported validation methods
Horizon validates domains with the CNAME or TXT DNS methods.
-
A domain that already holds a validation is re-validated with its own method, regardless of the method configured on the provider.
-
The configured method only applies to domains that were never validated, or whose previous validation used a method Horizon cannot drive (e.g. email).
-
When a validation order is already in progress on Sectigo, Horizon reuses its challenge instead of starting a new one. If that order uses a method Horizon cannot drive, the validation fails and the order is left untouched.
| Sectigo checks pending validations every 5 minutes. Set the DCV Policy execution timeout accordingly. |
How to configure a Sectigo DCV Provider
1. Log in to Horizon Administration Interface.
2. Access DCV Providers from the drawer or card: .
3. Click on .
4. Fill in the mandatory fields.
General
-
Name* (string input):
Enter a meaningful provider name. It must be unique for each DCV provider. Horizon uses the name to identify the provider. -
Type* (select):
SelectSectigo.
Configuration
-
Endpoint* (string input):
Enter the Sectigo Certificate Manager API base URL (e.g.https://admin.enterprise.sectigo.com). -
OAuth token endpoint (string input):
URL used to retrieve OAuth access tokens. Defaults to the Sectigo SSO token endpoint. -
Credentials* (select):
SelectLogincredentials containing the API client ID as login and the client secret as password. -
DCV method* (select):
Select the default validation method,CNAMEorTXT. See Supported validation methods. -
Organization ID (string input):
Restrict the domains to those of a Sectigo organization. When empty, all the domains of the account are listed. -
Timeout* (finite duration):
Maximum time Horizon waits for a response from the Sectigo API. -
Proxy (select):
The HTTP/HTTPS proxy to use to reach the Sectigo API, if any.
5. Click on the save button.
You can edit or delete
the Sectigo DCV Provider.
|
When Organization ID is empty, every never-validated domain of the account is selected by the DCV Policy. Use the policy domain filter to restrict the validated domains and the associated license consumption. |
|
You cannot delete a DCV Provider that is referenced by an existing DCV Policy. |