GlobalSign MSSL CA
Configuring GlobalSign MSSL
-
Go to
(Menu) > SIGN+ > ADMINISTRATION > Certificate
Authority.
-
From the displayed CA, Select GlobalSign.
The GlobalSign home page is displayed.
- Click the GlobalSign MSSL tab.
-
Click the Configure Now button or +Add icon from the middle
or top-right of the page respectively.
The GlobalSign MSSL configuration page is displayed.

-
Update the following details in the General
Information section as described in the table.
Table 1. General Information - Field Description Table Fields Description *CA Account name A unique name to identify the CA setting. No special characters other than ‘.’, ‘-’,’_’ are allowed. The name should not start with special characters. *Purpose/Usage Certificate Type for which CLM actions will be enabled. For example, server and clients Proxy Required Enable this field if the CA communication needs to happen via Proxy. The proxy details configured in general settings will be used for communication. Data Center (AppViewX's CA agent) Select the data center through which the CA communication needs to happen. *: Mandatory fields -
Update the following details in the CA Configuration
section as described in the table.
Fields Description *SSL URL Base URL of the SSL API *User Name Provide a username of the GCC to communicate with the CA. *Password Provide a password for the GCC to communicate with the CA. *: Mandatory fields - Once all the details are configured, click Save.
-
In GlobalSign MSSL, we can now fetch profiles and domains by clicking on
the Fetch Profiles and Domain button.
Note: The supported CSR key types are RSA 2048-8192, ECC P-256, ECC P-384 .
Validating GlobalSign MSSL
-
Go to
(Menu) > SIGN+ > ADMINISTRATION > Certificate
Authority.
-
From the displayed CA, Select GlobalSign.
The GlobalSign home page is displayed.
-
In the Status column of the grid with the listed accounts, click
GlobalSign MSSL from the left pane of the page.
The GlobalSign MSSL home page is displayed.

- In the Status column of the grid with the listed accounts, click Check to validate the CA setting that is created.
-
CA communication will be validated and the Connection Status will be shown
as either Success or Failure.
Limitations
| Case/Ticket number | Fix Description |
|---|---|
| CA Setting Update | Users need to click on the Cancel
button once the MSSL domain/profile. ID details are fetched from
the GlobalSign MSSL account. If the user clicks the Update
button, MSSL domain/profile ID details will be removed from
the associated policy. The steps to follow to update CA
settings are as follows:
|
| Default CA policy mapping | The default CA policy is defined with all available values selected and validity data is mapped based on commonly used validity. Hence, it will not have values equivalent to API documents or CA portals. This can be modified or updated in the application accordingly to the default CA policy if changes are required. |
| Email Address | The email address provided in the email address field on the enrollment page is not considered as the primary email value during CLM actions, instead, the email address field defined in the contact information of the logged-in user will be used. The help info message besides the Email address field on enroll/edit page is as – “If the user email address is configured, that will be used for GlobalSign CA approval actions. If the user email is not configured, then the email address provided in this field will be used" - the second part is not valid anymore. |