Going with GoDaddy
GoDaddy is one of the more popular sources for SSL certificates that support remote configuration. But GoDaddy doesn't take security lightly and will do a good bit of homework to validate that you are authorizated to recieve a Deluxe High-Assurance certificate on behalf of your organization. In order to make your purchasing process smooth and successful, here are some tips.
Bill York wrote an excellent blog on how to order such a certificate from GoDaddy that can be found at: http://communities.intel.com/openport/blogs/proexpert/2008/03/03/steps-to-purchase-a-godaddy-certificate-for-the-purpose-of-vpro-remote-configuration. Start by reading this article to familiarize yourself with the technical steps to complete the order. There are some tips below for setting up a new account that you may want to refer to as you start to follow his steps.
GoDaddy performs a good deal of "due diligence" research before they will issue a Deluxe High-Assurance SSL certificate. You can help to ensure the ordering process goes smoothly by anticipating the GoDaddy requirements to facilitate their research.
The "checks" that GoDaddy needs to perform are: domain authorization, corporate document approval, and online and verbal phone verification. You can see the on-going status of these steps when you log into your GoDaddy account after placing your order. As each step is completed, the icon next to that step will change in the Certification Steps Status page, shown below:
Account Setup
But prior to even ordering your SSL certificate, if you have to create a new account, be sure to use your company's formal legal name. GoDaddy will attempt to look up the company in a database, such as your state's list of registered companies maintained by the Secretary of State to see if your company is established. If not found, you may need to supply a letter of authorization from the company on letterhead for "Corporate Documents Approval" (see below).Also be careful with your company address and phone number. GoDaddy will lookup your company in a online phone directory for the "Corporate Phone Number Found" step. If your business and location are listed with a phone number where you can be reached, you are in good shape since they are going to want to call a published phone number and be transferred to your extension.
If you are in a remote office that is not listed in a directory, be prepared to supply a phone bill in your name where you can be reached instead. Your mobile or home phone may be used if you cannot get a transferred call from an office that resolves to your business in a db like Yellowpages.com or Yellowbook.com. If you know that your address and office number will not be found in an online directory, have a copy of a phone bill (mobile or home) on an account in your name available to fax to them.
When ordering your Deluxe High-Assurance SSL certificate, be sure to follow the instructions from the articles shown above to generate the CSR and specify the appropriate OU to equal "Intel(R) Client Setup Certificate". Once the order is placed, you can start to monitor the status of your order.
Administrative Approval
As soon as you place the order, check the WHOIS lookup for your domain by using the link on the form or another method. Then, call or email your internal administrative contact for the domain to let them know to expect an email from GoDaddy requesting authorization for the certificate. Ask that person in your organization to let you know when they've replied and log back in to check the status after they do. The first three steps, "CSR Being Generated", "WHOIS Lookup Being Performed", and "Awaiting Administrative Approval," should be completed at this point. If not, you may want to call GoDaddy Technical Support to let them know of your progress.Corporate Document Approval
At that time while you have GoDaddy on the phone, inquire as to whether they can find your company in the Sec. of State database and if not, verify what will substitute for Corporate Document Approval. In some cases, be prepared to submit Articles of Incorporation or copies of a SEC filing at this stage if necessary.In other cases, you will need to fax a letter that includes the date and CommonName for the certificate signed by the department manager that authorizes you getting the certificate. This manager's position or title will need to be verified through either an on-line directory on your company's web site or by calling your HR department or contact. If you know that person's position or title cannot be verified on-line by GoDaddy, include the phone number for HR in the letter.
Corporate Phone Number Found
At this point, GoDaddy may need to forward your corporate documents to an administrative researcher within GoDaddy and there may be a delay for the documents to be verified. After this is done, and your "Corporate Document Approval" step status changes from In Progress to Completed, you may want to call Technical Support to help them find the best phone number to reach you at in an online directory. If this doesn't work for your phone number, ask for the Request for Verification form that you can complete and fax with the phone bill described above.Once they have found the right number to call or received your phone bill and Request for Verification form, all that is left is to wait for the call. Verbally verify your identity and soon the certificate will be issued. In some cases, GoDaddy has sent an additional certificate with a P7X file extension, along with instructions on how to install it. I've not seen a case where the installation of this was necessary, and it may only serve to confuse you. You should only need to install the SSL cert for your domain in accordance with the documentation for your management console or provisioning server such as Intel's Setup and Configuration Service (SCS).
Remember, your certificate needs to have a CN matching the domain suffix of the machine where it will be installed and an OU matching "Intel(R) Client Setup Certificate" in the details of the Subject field. Also, the cert will need to "chain up" to the GoDaddy trusted root cert with a thumbprint matching one of the pre-installed trusted root CA thumbprints in the AMT firmware. For more information about certificate format requirements, installation of this cert, and other PKI-related questions regarding remote configuration, as alway,s a good place to look online is here at the vPro Expert Center.
Best of luck in getting going with GoDaddy!





