This page lists the permissions required by Certificate Manager and the Identity and Access Management roles that encapsulate them.
Permissions
This section lists the permissions required to perform specific operations in Certificate Manager.
| Operation and method | Resource | Permission |
|---|---|---|
Create a certificatecertificates.create |
Certificates | certificatemanager.certs.create on the target Google Cloud project.
If using DNS authorization, also requires certificatemanager.dnsauthorizations.use
on each associated DNS authorization. |
List certificatescertificates.list |
Certificates | certificatemanager.certs.list on the target Google Cloud project |
View certificates in the consoleserviceusage.quotas.get,monitoring.timeSeries.list |
Certificates | serviceusage.quotas.get and monitoring.timeSeries.list on the target Google Cloud project |
Retrieve a certificatecertificates.get |
Certificates | certificatemanager.certs.get on the target certificate |
Update a certificatecertificates.patch |
Certificates | certificatemanager.certs.update on the target certificate |
| Attach a certificate to a resource | Certificates | certificatemanager.certs.use on the target certificate |
Delete a certificatecertificates.delete |
Certificates | certificatemanager.certs.delete on the target certificate |
Create a certificate mapcertificateMaps.create |
Certificate maps | certificatemanager.certmaps.create on the target Google Cloud project |
List certificate mapscertificateMaps.list |
Certificate maps | certificatemanager.certmaps.list on the target Google Cloud project |
Retrieve a certificate mapcertificateMaps.get |
Certificate maps | certificatemanager.certmaps.get on the target certificate map |
Update a certificate mapcertificateMaps.patch |
Certificate maps | certificatemanager.certmaps.update on the target certificate map |
| Attach a certificate map to a resource | Certificate maps | certificatemanager.certmaps.use on the target certificate map |
Delete a certificate mapcertificateMaps.delete |
Certificate maps | certificatemanager.certmaps.delete on the target certificate map |
Create a certificate map entrycertificateMaps.certificateMapEntries.create |
Certificate map entries | certificatemanager.certmapentries.create on the target certificate map
and certificatemanager.certs.use on each associated certificate. |
List certificate map entriescertificateMaps.certificateMapEntries.list |
Certificate map entries | certificatemanager.certmapentries.list on the target certificate map |
Retrieve a certificate map entrycertificateMaps.certificateMapEntries.get |
Certificate map entries | certificatemanager.certmapentries.get on the target certificate map entry |
Update a certificate map entrycertificateMaps.certificateMapEntries.patch |
Certificate map entries | certificatemanager.certmapentries.update on the target certificate map entry
and certificatemanager.certs.use on each associated certificate. |
Delete a certificate map entrycertificateMaps.certificateMapEntries.delete |
Certificate map entries | certificatemanager.certmapentries.delete on the target certificate map entry |
Create a DNS authorizationdnsAuthorizations.create |
DNS authorizations | certificatemanager.dnsauthorizations.create on the target Google Cloud project |
List DNS authorizationsdnsAuthorizations.list |
DNS authorizations | certificatemanager.dnsauthorizations.list on the target Google Cloud project |
Retrieve a DNS authorizationdnsAuthorizations.get |
DNS authorizations | certificatemanager.dnsauthorizations.get on the target DNS authorization |
Update a DNS authorizationdnsAuthorizations.patch |
DNS authorizations | certificatemanager.dnsauthorizations.update on the target DNS authorization |
Delete a DNS authorizationdnsAuthorizations.delete |
DNS authorizations | certificatemanager.dnsauthorizations.delete on the target DNS authorization |
Create a certificate issuance configcertificateIssuanceConfigs.create |
Certificate issuance configs | certificatemanager.certissuanceconfigs.create on the target Google Cloud project |
List certificate issuance configscertificateIssuanceConfigs.list |
Certificate issuance configs | certificatemanager.certissuanceconfigs.list on the target Google Cloud project |