GCP Certificate Authority Service PKI
Prerequisites
-
You need a CA pool containing at least one enabled certificate authority, and to retrieve the GCP project ID and the location hosting it. The pool automatically selects an enabled certificate authority at issuance time.
-
You need to create a service account using the GCP IAM, and grant it the appropriate permissions on the CA pool, as documented here. Typically, these can be granted through the CA Service Certificate Requester role (
roles/privateca.certificateRequester) for issuance and the CA Service Certificate Manager role (roles/privateca.certificateManager) for revocation, or through the individual following permissions:-
privateca.certificates.create -
privateca.certificates.list -
privateca.certificates.update
-
-
You need to retrieve the JSON key file of that service account, unless Horizon runs on GCP and authenticates through Application Default Credentials.
|
Refer to the editor’s documentation to configure the PKI side here. |
|
The health check of this connector only lists the certificates of the CA pool. It succeeds with an empty list even when the service account lacks the issuance or revocation permissions, so a healthy connector does not guarantee that enrollment will succeed. |
Limitations
-
Only the following Subject DN fields are managed:
CN,C,O,OU,L,STandSTREET. Any other DN element is ignored and not sent to GCP. -
Subject DN fields are single-valued on GCP. For multi-valued fields, the exceeding items will be ignored.
-
Only the following
subjectAltNamesare managed:DNS,URI,RFC822NameandIPaddress.msUPN,msGUIDandregisteredIDare not supported. -
Certificate extensions and policies are defined by the CA pool or by the certificate template, not by Horizon.
-
All limitations induced by the use of the GCP Certificate Authority Service API.
Create the PKI connector
1. Log in to Horizon Administration Interface.
2. Access PKI from the drawer or card: .
3. Click on .
4. Select the correct PKI type.
5. Click on the next button
General tab
6. Fill in the common mandatory fields:
-
Connector Name* (string input):
Choose a meaningful connector name allowing to identify the mapping between the PKI and the Certificate Profile. It must be unique and must not contain spaces. -
Proxy (string select):
If the PKI is not directly reachable from Horizon, you can set up an HTTP/HTTPS proxy to properly forward the traffic. -
PKI Queue (string select):
The PKI Queue used to manage the PKI Requests (enrollment, revocation). -
Timeout (finite duration):
Represents a predefined interval of time without a PKI response, when the time has passed "Horizon" will cease trying to establish the communication. Must be a valid finite duration.
7. Click on the next button
Details tab
8. Fill in all mandatory fields:
-
Project ID* (string input):
ID of the GCP project hosting the CA pool. It may differ from the project of the service account used to authenticate. -
Location* (string input):
Location of the CA pool, for exampleeurope-west1. -
CA pool* (string input):
ID of the CA pool to use for certificate issuance. -
Certificate lifetime* (finite duration):
Validity duration applied to every certificate issued through this connector. Must be a valid finite duration. There is no default value. -
Certificate template (string input):
The CAS certificate template to apply. Enter either its short name or its full resource path, in the formprojects/<project>/locations/<location>/certificateTemplates/<template>. -
Endpoint (string input):
Overrides the endpoint used to reach the API. By default, the standard Google Cloud endpoint is used.
9. Click on the next button.
Authentication tab
10. Fill in the PKI-authentication fields:
-
Credentials (select):
SelectAPI Tokencredentials whose token holds the full content of the service account JSON key file. If left empty, Horizon falls back to the Application Default Credentials of the machine it runs on, which covers workload identity. -
Impersonated service account (string input):
Email of the service account to impersonate. Leave empty not to use impersonation. -
Impersonation lifetime (finite duration):
Validity duration of the impersonated token. Mandatory when an impersonated service account is set. Must be a valid finite duration and must not exceed 12 hours.
11. Click on the save button.
You can edit , duplicate
or delete
the GCP Certificate Authority Service PKI connector.