Skip to content

Google Certificate Authority Service

Google Certificate Authority Service Integration

Section titled “Google Certificate Authority Service Integration”

Integrate Google Cloud Certificate Authority Service (CAS) with SSL-CLM to:

  • Issue private certificates for GCP and hybrid workloads
  • Renew certificates automatically
  • Revoke certificates
  • Sync certificate inventory from Google CAS

Google CAS integrates via the Google Cloud API. No agent is required.


SSL-CLM Platform
│
│ (Google Cloud API / HTTPS)
▼
Google Certificate Authority Service
│
▼
CA Pool → Certificate Authority

  • Google Cloud project with Certificate Authority Service enabled
  • CA Pool created with at least one active CA
  • Service account with appropriate IAM roles
  • Network access from SSL-CLM backend to Google Cloud APIs

Create a service account with the following roles:

RolePurpose
roles/privateca.certificateRequesterIssue certificates
roles/privateca.certificateManagerRevoke certificates, list certs
roles/privateca.auditorRead CA pool and CA details

Create and download a JSON key for the service account.


Step 2 — Create Certificate Authority in SSL-CLM

Section titled “Step 2 — Create Certificate Authority in SSL-CLM”
  1. Navigate to Infrastructure → Certificate Authorities
  2. Click + Add CA
  3. Select Google Cloud CAS from the type cards
  4. Fill in the configuration:
FieldDescriptionExample
NameFriendly nameGCP CAS Production
Project IDGCP project IDmy-project-123
LocationRegionus-central1
CA Pool IDCA Pool identifiermy-ca-pool
CA ID(Optional) Specific CA in the poolmy-subordinate-ca
Service Account JSONFull service account key JSON(stored encrypted)
Discovery IntervalHours between inventory syncs24
  1. Click Test Connection to verify
  2. Click Save

  1. Navigate to Certificates → + New Certificate
  2. Select Issue from CA
  3. Choose the Google CAS CA
  4. Fill in subject and SAN details
  5. Set validity period
  6. Submit

SSL-CLM will:

  1. Generate a CSR
  2. Call the CAS API’s CreateCertificate method
  3. Provide the CSR and lifetime configuration
  4. Receive the issued certificate and chain
  5. Store in inventory

When revocation is requested:

  1. SSL-CLM calls the CAS RevokeCertificate API
  2. Google CAS updates the certificate status and publishes to CRL
  3. SSL-CLM updates the certificate status to REVOKED

  • CA Pool — A group of CAs that share issuance policy and load-balance issuance
  • CA — An individual Certificate Authority within a pool

If you specify only the CA Pool ID (leaving CA ID empty), Google CAS will select the appropriate CA from the pool automatically. Specify a CA ID to force issuance from a specific CA.


Google CAS offers two tiers:

TierUse CasePricing
DevOpsHigh-volume, short-lived certs (< 30 days)~$0.10/cert
EnterpriseLong-lived certs, HSM-backed keys, audit~$2-3/cert

Choose based on your certificate validity and compliance requirements.


IssuePossible CauseResolution
Permission deniedService account lacks rolesAdd required IAM roles
CA Pool not foundWrong project, location, or pool IDVerify all identifiers
API not enabledCAS API not enabled on projectEnable privateca.googleapis.com
Quota exceededToo many certificate requestsCheck GCP quotas, request increase