Provision to a Google Cloud Classic Load Balancer
Focus
Focus
Next‑Gen Trust Security

Provision to a Google Cloud Classic Load Balancer

Table of Contents

Provision to a Google Cloud Classic Load Balancer

After you create a Google Cloud Classic Load Balancer machine in Next-Gen Trust Security, you can provision certificates to it. Provisioning allows Next-Gen Trust Security to deploy certificates directly to your Google Cloud load balancers, automating certificate deployment and renewal.

Before You Begin

  • Your Google Cloud Classic Load Balancer machine must be created and verified in Next-Gen Trust Security. See Create a Google Cloud Classic Load Balancer machine.
  • The machine must have "VERIFIED" status under the Access tab.
  • You must have a certificate with a private key available in Next-Gen Trust Security:
    • Next-Gen Trust Security-generated certificates
    • User-imported certificates with private keys
  • You must have appropriate permissions to provision certificates (System Administrator, PKI Administrator, or Resource Owner for certificates you own).
  • Your target load balancer resources must already exist in GCP:
    • Global Target HTTPS Proxy
    • Global Target SSL Proxy, or
    • Regional Target HTTPS Proxy
Note:
  • Provisioning creates a new classic SSL certificate resource in GCP with a timestamp suffix appended to the certificate name.
  • During renewal, Next-Gen Trust Security creates a new timestamped certificate, updates the proxy reference, and removes the previous certificate version.
  • Only classic SSL certificates are supported. Certificate Manager certificates and Certificate Map attachment methods are not available.

Provision a Certificate

To provision a certificate to your Google Cloud Classic Load Balancer, follow these steps:
  1. Sign in to Next-Gen Trust Security.
  2. Click Insights > Certificate Installations > Machines.
  3. Select the Google Cloud Classic Load Balancer machine where you want to provision the certificate.
  4. Select the Installations tab.
  5. Click Provision.
  6. Search for and select the certificate you want to provision.
  7. Configure the GCP Certificate Location:
    1. From the Certificate Type drop-down, select one of the following:
      • Compute Engine SSL Certificate (Global) – For global load balancers
      • Compute Engine SSL Certificate (Regional) – For regional load balancers
    2. In the Certificate Name field, enter a name for the SSL certificate resource in GCP.
      Note: Next-Gen Trust Security automatically appends a timestamp suffix (YYYYMMDD-HHMMSS) to the certificate name to support versioning during renewals.
    3. (Conditional) If you selected Compute Engine SSL Certificate (Regional), select the Location (region) where the certificate should be created from the drop-down. This must match the region of your Regional Target HTTPS Proxy.
  8. Configure the Load Balancer Binding:
    1. From the Proxy Type drop-down, select one of the following:
      • Global Target HTTPS Proxy – For global HTTPS load balancers
      • Global Target SSL Proxy – For global TCP SSL load balancers
      • Regional Target HTTPS Proxy – For regional HTTPS load balancers
    2. From the Proxy Name drop-down, select the target proxy where the certificate should be attached.
      Note: The proxy list is dynamically populated based on your selected proxy type and region.
    3. (Conditional) If you selected Regional Target HTTPS Proxy, select the Proxy Region from the drop-down. This must match the location you selected for the certificate.
    Note: The Certificate Attachment Method is automatically set to Classic SSL Certificates. This is the only supported method for Google Cloud Classic Load Balancers.
  9. (Optional) Enable Push certificate on save to provision the certificate immediately after clicking Save.
  10. Click Save.
  11. If you enabled Push certificate on save, the provisioning begins immediately. Otherwise, click Push from the Installations tab to provision the certificate.
  12. Monitor the installation status:
    • Pending – The provisioning request is queued
    • Installing – The certificate is being deployed to GCP
    • Installed – The certificate was successfully provisioned
    • Error – Provisioning failed (review the Event Logs for details)

Verify the Certificate in GCP

To verify that the certificate was successfully provisioned:
  1. For global certificates, run:
    gcloud compute ssl-certificates list --global --project=YOUR_PROJECT_ID
  2. For regional certificates, run:
    gcloud compute ssl-certificates list --regions=REGION_NAME --project=YOUR_PROJECT_ID
  3. Verify the proxy reference:
    • For Global Target HTTPS Proxy:
      gcloud compute target-https-proxies list --project=YOUR_PROJECT_ID
    • For Global Target SSL Proxy:
      gcloud compute target-ssl-proxies list --project=YOUR_PROJECT_ID
    • For Regional Target HTTPS Proxy:
      gcloud compute target-https-proxies list --filter='region:REGION_NAME' --project=YOUR_PROJECT_ID

Schedule Certificate Provisioning

You can configure Next-Gen Trust Security to automatically provision certificates on a recurring schedule:
  1. From your machine's Provisioning tab, enable the Schedule toggle.
  2. Configure the schedule:
    • Repeat every: Select Day, Week, or Month
    • At time: Specify the time in UTC
    • (Conditional) For weekly schedules, select the day of the week
    • (Conditional) For monthly schedules, select the day of the month
  3. Click Save.
The scheduled provisioning job runs at the specified time and provisions any certificates that have been configured but not yet deployed.
Tip: Combine scheduled provisioning with auto-renewal to fully automate certificate lifecycle management for your Google Cloud load balancers.

What's Next?