What is Certificate Authority Service?
Certificate Authority Service (CAS) is a managed, scalable Google Cloud service for creating and managing private certificate authorities. It enables automated issuance of TLS and mTLS certificates for internal services, workloads, and devices without operating your own PKI infrastructure.
CAS offers two operation tiers: the DevOps tier is designed for high-volume, short-lived certificates in microservice environments but does not include certificate lifecycle management such as revocation or CRLs. The Enterprise tier provides full lifecycle management including revocation and supports customer-managed CA keys via Cloud KMS — ideal for longer-lived certificates used for device and user identities. The tier is set when the CA pool is created and cannot be changed afterward.
Core Features
- Managed root and subordinate CAs with configurable policy controls and certificate templates
- HSM-backed key storage via Cloud HSM (FIPS 140-2 Level 3 validated)
- Automated certificate issuance and renewal
- Integration with Certificate Manager, GKE, and Anthos Service Mesh / Cloud Service Mesh
- RESTful API and Terraform support
Typical Use Cases
Service Mesh mTLS: Issuance and rotation of certificates for Anthos Service Mesh or Cloud Service Mesh to ensure secure service-to-service communication.
IoT Device Certificates: Scalable certificate issuance for many IoT devices, typically via the Enterprise tier with lifecycle management.
Zero-Trust Architectures: Foundation for identity-based access controls with client certificates in CI/CD pipelines (DevOps tier) or for user and device identities (Enterprise tier).
Benefits
- No need to operate your own PKI infrastructure
- Two operation tiers for different throughput and lifecycle requirements
- HSM support for enhanced key security
- Native integration with other Google Cloud services
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you with Certificate Authority Service: selecting the right tier, architecture, migration, operations, and cost optimization.
Available Tiers & Options
DevOps
- High throughput for short-lived certificates
- Ideal for microservices with frequent certificate rotation
- No certificate lifecycle management (no listing, describing, or revoking certificates)
- No customer-managed CA keys via Cloud KMS
Enterprise
- Full certificate lifecycle management including revocation
- Customer-managed CA keys via Cloud KMS
- HSM support
- Lower QPS throughput per CA than the DevOps tier
Typical Use Cases
Frequently Asked Questions
What is Certificate Authority Service?
A managed Google Cloud service for creating and managing private certificate authorities (CAs) to issue TLS and mTLS certificates within an organization. The tier (DevOps or Enterprise) is set when the CA pool is created and cannot be changed afterward.
When should I choose the DevOps vs. Enterprise tier?
The DevOps tier is suited for high-volume, short-lived certificates in microservice environments with frequent rotation, but does not offer certificate lifecycle management (no revocation, no CRLs). The Enterprise tier is designed for longer-lived certificates where lifecycle management and revocation matter, such as for device and user identities.
How does the service integrate with service mesh and GKE?
The service integrates with Anthos Service Mesh or Cloud Service Mesh for mTLS between workloads, as well as with GKE for automatic certificate issuance and renewal.
Does the service support HSM-protected keys?
Yes, CA keys can be stored using Cloud HSM, which is FIPS 140-2 Level 3 validated and available in regions across the Americas, Europe, and Asia Pacific. The DevOps tier only allows a service-managed key, while the Enterprise tier also supports a customer-managed key via Cloud KMS.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
