Google Certificate Authority Service
Google Certificate Authority Service Integration
Section titled “Google Certificate Authority Service Integration”Integrate Google Cloud Certificate Authority Service (CAS) with SSL-CLM to:
- Issue private certificates for GCP and hybrid workloads
- Renew certificates automatically
- Revoke certificates
- Sync certificate inventory from Google CAS
Google CAS integrates via the Google Cloud API. No agent is required.
Architecture
Section titled “Architecture”SSL-CLM Platform││ (Google Cloud API / HTTPS)▼Google Certificate Authority Service│▼CA Pool → Certificate AuthorityPrerequisites
Section titled “Prerequisites”- Google Cloud project with Certificate Authority Service enabled
- CA Pool created with at least one active CA
- Service account with appropriate IAM roles
- Network access from SSL-CLM backend to Google Cloud APIs
Step 1 — Create Service Account
Section titled “Step 1 — Create Service Account”Create a service account with the following roles:
| Role | Purpose |
|---|---|
roles/privateca.certificateRequester | Issue certificates |
roles/privateca.certificateManager | Revoke certificates, list certs |
roles/privateca.auditor | Read CA pool and CA details |
Create and download a JSON key for the service account.
Step 2 — Create Certificate Authority in SSL-CLM
Section titled “Step 2 — Create Certificate Authority in SSL-CLM”- Navigate to Infrastructure → Certificate Authorities
- Click + Add CA
- Select Google Cloud CAS from the type cards
- Fill in the configuration:
| Field | Description | Example |
|---|---|---|
| Name | Friendly name | GCP CAS Production |
| Project ID | GCP project ID | my-project-123 |
| Location | Region | us-central1 |
| CA Pool ID | CA Pool identifier | my-ca-pool |
| CA ID | (Optional) Specific CA in the pool | my-subordinate-ca |
| Service Account JSON | Full service account key JSON | (stored encrypted) |
| Discovery Interval | Hours between inventory syncs | 24 |
- Click Test Connection to verify
- Click Save
Step 3 — Issue Certificates
Section titled “Step 3 — Issue Certificates”- Navigate to Certificates → + New Certificate
- Select Issue from CA
- Choose the Google CAS CA
- Fill in subject and SAN details
- Set validity period
- Submit
SSL-CLM will:
- Generate a CSR
- Call the CAS API’s
CreateCertificatemethod - Provide the CSR and lifetime configuration
- Receive the issued certificate and chain
- Store in inventory
Step 4 — Revoke Certificates
Section titled “Step 4 — Revoke Certificates”When revocation is requested:
- SSL-CLM calls the CAS
RevokeCertificateAPI - Google CAS updates the certificate status and publishes to CRL
- SSL-CLM updates the certificate status to REVOKED
CA Pool vs. CA
Section titled “CA Pool vs. CA”- CA Pool — A group of CAs that share issuance policy and load-balance issuance
- CA — An individual Certificate Authority within a pool
If you specify only the CA Pool ID (leaving CA ID empty), Google CAS will select the appropriate CA from the pool automatically. Specify a CA ID to force issuance from a specific CA.
Google CAS offers two tiers:
| Tier | Use Case | Pricing |
|---|---|---|
| DevOps | High-volume, short-lived certs (< 30 days) | ~$0.10/cert |
| Enterprise | Long-lived certs, HSM-backed keys, audit | ~$2-3/cert |
Choose based on your certificate validity and compliance requirements.
Troubleshooting
Section titled “Troubleshooting”| Issue | Possible Cause | Resolution |
|---|---|---|
| Permission denied | Service account lacks roles | Add required IAM roles |
| CA Pool not found | Wrong project, location, or pool ID | Verify all identifiers |
| API not enabled | CAS API not enabled on project | Enable privateca.googleapis.com |
| Quota exceeded | Too many certificate requests | Check GCP quotas, request increase |