The typical implementation process for GlobalSign Managed PKI software involves the following steps:
Account Setup: Create and configure an Enterprise PKI (EPKI) account through the GlobalSign Certificate Center (GCC). This includes registering your organization and purchasing a license.
Profile Creation: Establish pre-vetted certificate profiles for different use cases, such as SSL/TLS, S/MIME, or device authentication, to streamline certificate issuance.
Integration: Integrate the platform with existing systems like Active Directory (AD), Mobile Device Management (MDM) platforms (e.g., Intune, VMware Workspace ONE), or other APIs for automation.
Certificate Issuance: Begin issuing certificates instantly using pre-vetted profiles and domains. Configure workflows for automated issuance, renewal, and revocation as needed.
Testing and Validation: Test the system by issuing and managing certificates to ensure proper functionality and integration with existing infrastructure.
Training and Onboarding: Train administrators on using the GCC portal, managing profiles, and leveraging automation tools like the Auto Enrollment Gateway (AEG).
Deployment: Deploy certificates across devices, users, or applications in production environments. Use automation tools to scale deployment efficiently.
GlobalSign Managed PKI can be customized to fit specific business needs, offering extensive flexibility and scalability.
Custom PKI Hierarchies: Organizations can create dedicated private roots and intermediate CAs for internal use or branded public intermediates that chain to GlobalSign’s trusted roots, providing tailored trust models for specific ecosystems.
Multiple Organization Profiles: The platform allows managing multiple departments or entities under one account, enabling centralized control while maintaining individual profiles for different business units or projects.
Flexible Certificate Types: Supports a variety of certificates, including SSL/TLS (EV, OV, DV), S/MIME for email encryption, document signing, device authentication, and smartcard logon, catering to diverse use cases.
Configurable Certificate Attributes: Users can define certificate validity periods, key usages, and extended key usages to meet specific security policies and compliance requirements.
Automation and Integration: The platform integrates with Active Directory (AD), Mobile Device Management (MDM) systems (e.g., Intune, VMware Workspace ONE), and APIs for automating certificate lifecycles and workflows in mixed environments.
Customizable Trust Models: Supports both public and private trust requirements with options to host dedicated private hierarchies or leverage GlobalSign’s public root infrastructure for broader compatibility.
Granular User Permissions: Administrators can define user roles and permissions at the domain or profile level, ensuring only authorized personnel can issue, renew, or revoke certificates.
Scalable Licensing Options: Offers flexible purchasing models such as pay-as-you-go, deposit-based plans, or unlimited issuance licenses to accommodate varying budgetary needs.
Pre-Vetted Domains and Profiles: Enables instant issuance of certificates tailored to specific project or departmental needs without delays from manual vetting processes.
GlobalSign Managed PKI
By GMO Internet Group, Inc
GlobalSign offers a suite of training and support resources to assist new users in effectively utilizing their Managed Public Key Infrastructure (PKI) platform:
Support Knowledge Base: GlobalSign's Support Knowledge Base provides detailed articles and guides on various topics related to their products and services. Users can access information on certificate management, platform features, and troubleshooting steps.
Webinars: To enhance user understanding of PKI concepts and best practices, GlobalSign offers webinars covering topics such as advanced cryptography, IoT device security, and certificate management strategies. These sessions are available
Administrative Guides: For users enrolled in GlobalSign's Enterprise PKI (EPKI) services, administrative guides are available to assist in setting up and managing ordering and other administrative functions within their accounts.
GlobalSign Managed Public Key Infrastructure (PKI) platform incorporates several robust security measures to protect data and ensure the integrity of digital communications:
Data Encryption and Signing: The platform utilizes advanced data encryption techniques to render information unreadable to unauthorized parties. Only recipients possessing the corresponding private keys can decrypt and access the data, ensuring confidentiality. Additionally, data signing capabilities verify the authenticity and integrity of the information, preventing tampering during transmission.
Strong Authentication Mechanisms: GlobalSign's Managed PKI employs digital certificates as electronic credentials to authenticate users, devices, and servers. This strong authentication framework ensures that only authorized entities can access critical systems and data, enhancing overall security.
Certificate Lifecycle Management: The platform offers automated certificate lifecycle management, encompassing issuance, renewal, and revocation processes. This automation minimizes human error and reduces the likelihood of security breaches arising from expired or mismanaged certificates.
Integration with Zero Trust Security Models: By integrating with Zero Trust security frameworks, GlobalSign's PKI adds layers of protection and authentication to organizational systems and data. This approach ensures that every access request is thoroughly verified, regardless of its origin, aligning with modern security best practices.
GlobalSign policies on data ownership and portability within its Managed Public Key Infrastructure (PKI) services are designed to respect user rights and ensure compliance with applicable data protection regulations:
Data Ownership: GlobalSign acknowledges the importance of personal data protection and outlines its practices in the GlobalSign Data Protection Policy. This policy details GlobalSign's commitment to safeguarding personal data collected during the provision of PKI products and services. It specifies the types of information collected, the purposes for which it is used, and the measures taken to protect this data. While the policy emphasizes data protection, it does not explicitly address data ownership rights. However, by adhering to data protection principles, GlobalSign ensures that personal data is handled responsibly and in compliance with relevant laws.
Data Portability: GlobalSign's Privacy Policy outlines the company's commitment to respecting user privacy and details the rights of individuals concerning their personal data. The policy informs users about their rights, including access to their data, correction of inaccuracies, and, where applicable, the right to data portability. Data portability allows individuals to obtain and reuse their personal data across different services. While the policy emphasizes privacy practices, it does not provide specific procedures for data portability within the Managed PKI services.
The terms and conditions for contract renewal and cancellation for GlobalSign Managed PKI are outlined through various policies and practices.
Renewal Process: Certificates can be renewed through the GlobalSign Certificate Center (GCC) within a renewal period of 90 days before expiration. Notifications for upcoming renewals are provided, and administrators can manage renewals directly via the GCC dashboard.
Cancellation Policy: Orders can be canceled automatically within a 7-day refund period after the certificate is issued. Beyond this period, users must contact GlobalSign support to request cancellation. Refunds are processed based on the payment method, either by refunding credit card payments, canceling invoices, or crediting deposit accounts.
Subscriber Obligations: Subscribers must provide accurate information during the certificate request process and promptly notify GlobalSign of any changes or suspected misuse of their private key or certificate. Failure to comply with these obligations may result in revocation or termination of services.
Refund Policy: Subscribers dissatisfied with their issued certificates can request a refund within 7 days of issuance. Refunds exclude fees incurred by GlobalSign during the transaction.
GlobalSign Managed PKI adheres to the following compliance standards:
Key Compliance Standards Supported by GlobalSign's Managed PKI:
GlobalSign's Managed PKI offers data encryption and signing capabilities that help healthcare organizations protect sensitive patient information, aligning with HIPAA's stringent data protection mandates.
By implementing robust encryption and authentication mechanisms, GlobalSign's PKI solutions assist businesses in securing payment card data, supporting compliance with PCI DSS requirements.
GlobalSign's PKI solutions provide secure methods for data encryption and authentication, aiding businesses in protecting personal data and supporting compliance with GDPR.