Roles and permissions

This page lists the permissions required by Certificate Manager and the Identity and Access Management roles that encapsulate them.

Permissions

This section lists the permissions required to perform specific operations in Certificate Manager.

Operation and method Resource Permission
Create a certificate

certificates.create
Certificates certificatemanager.certs.create on the target Google Cloud project. If using DNS authorization, also requires certificatemanager.dnsauthorizations.use on each associated DNS authorization.
List certificates

certificates.list
Certificates certificatemanager.certs.list on the target Google Cloud project
View certificates in the console

serviceusage.quotas.get,
monitoring.timeSeries.list
Certificates serviceusage.quotas.get and monitoring.timeSeries.list on the target Google Cloud project
Retrieve a certificate

certificates.get
Certificates certificatemanager.certs.get on the target certificate
Update a certificate

certificates.patch
Certificates certificatemanager.certs.update on the target certificate
Attach a certificate to a resource Certificates certificatemanager.certs.use on the target certificate
Delete a certificate

certificates.delete
Certificates certificatemanager.certs.delete on the target certificate
Create a certificate map

certificateMaps.create
Certificate maps certificatemanager.certmaps.create on the target Google Cloud project
List certificate maps

certificateMaps.list
Certificate maps certificatemanager.certmaps.list on the target Google Cloud project
Retrieve a certificate map

certificateMaps.get
Certificate maps certificatemanager.certmaps.get on the target certificate map
Update a certificate map

certificateMaps.patch
Certificate maps certificatemanager.certmaps.update on the target certificate map
Attach a certificate map to a resource Certificate maps certificatemanager.certmaps.use on the target certificate map
Delete a certificate map

certificateMaps.delete
Certificate maps certificatemanager.certmaps.delete on the target certificate map
Create a certificate map entry

certificateMaps.certificateMapEntries.create
Certificate map entries certificatemanager.certmapentries.create on the target certificate map and certificatemanager.certs.use on each associated certificate.
List certificate map entries

certificateMaps.certificateMapEntries.list
Certificate map entries certificatemanager.certmapentries.list on the target certificate map
Retrieve a certificate map entry

certificateMaps.certificateMapEntries.get
Certificate map entries certificatemanager.certmapentries.get on the target certificate map entry
Update a certificate map entry

certificateMaps.certificateMapEntries.patch
Certificate map entries certificatemanager.certmapentries.update on the target certificate map entry and certificatemanager.certs.use on each associated certificate.
Delete a certificate map entry

certificateMaps.certificateMapEntries.delete
Certificate map entries certificatemanager.certmapentries.delete on the target certificate map entry
Create a DNS authorization

dnsAuthorizations.create
DNS authorizations certificatemanager.dnsauthorizations.create on the target Google Cloud project
List DNS authorizations

dnsAuthorizations.list
DNS authorizations certificatemanager.dnsauthorizations.list on the target Google Cloud project
Retrieve a DNS authorization

dnsAuthorizations.get
DNS authorizations certificatemanager.dnsauthorizations.get on the target DNS authorization
Update a DNS authorization

dnsAuthorizations.patch
DNS authorizations certificatemanager.dnsauthorizations.update on the target DNS authorization
Delete a DNS authorization

dnsAuthorizations.delete
DNS authorizations certificatemanager.dnsauthorizations.delete on the target DNS authorization
Create a certificate issuance config

certificateIssuanceConfigs.create
Certificate issuance configs certificatemanager.certissuanceconfigs.create on the target Google Cloud project
List certificate issuance configs

certificateIssuanceConfigs.list
Certificate issuance configs certificatemanager.certissuanceconfigs.list on the target Google Cloud project