Certificate Security
Certificate Manager
GCP Certificate Manager provisions and manages TLS/SSL certificates for Google Cloud Load Balancing, using certificate maps to bind certificates to target proxies. It supports Google-managed certificates (DNS or load-balancer authorization), self-managed certificates, and Public CA-issued certificates, with automated renewal and rotation. A 2nd-generation layer adds a certificate directory, inventory, and monitoring. It is purpose-built for load-balancer-attached TLS, not an enterprise-wide PKI store.
Google Cloud
Service information
Shortname: Certificate Manager
Huawei equivalent shortnames: CCM
Keywords: certificate, tls, pki, security
Differences vs Huawei
GCP Certificate Manager uses certificate maps that bind one or more certificates to external/global load balancer target proxies, with selection logic per SNI hostname. Huawei CCM treats certificates as a lifecycle repository and pushes them via one-click deployment to WAF, ELB, CDN, and VOD rather than through a declarative map object. The two therefore expose different data models and control-plane APIs; you cannot lift a GCP certificate map into Huawei as-is.
GCP offers Google-managed certificates with automated DNS/LB authorization and renewal, plus Public CA integration, and delegates private PKI to the separate Certificate Authority Service. Huawei CCM bundles public SSL certificates (issued through third-party CAs such as DigiCert, GlobalSign, and GeoTrust) and Private CA (PCA) into one product, with auto-update of multi-year certs deployed to other services but manual application per issuance. Private PKI boundaries and automation hooks differ between the platforms.
GCP Certificate Manager (2nd gen) provides a certificate directory, inventory view, monitoring metrics, and Cloud Logging integration for cert health; integration is optimized for Google Cloud Load Balancing and Certificate Authority Service. Huawei CCM surfaces expiration notifications, Cloud Trace Service (CTS) audit, and KMS/HSM-backed key storage, integrating with Huawei WAF, ELB, CDN, VOD, and DEW. Operational observability, key custody, and the set of deploy targets are not equivalent and must be re-planned.
Migration to Huawei
Inventory every GCP certificate map, certificate scope (managed, self-managed, or Public CA), target load balancers, and SNI routing rules. Huawei CCM is the closest equivalent for public SSL lifecycle and private PKI (PCA), but neither CCM nor any Huawei migration service offers an automated import from GCP Certificate Manager. Plan a manual re-issuance and redeployment effort, and decide which certs reissue via Huawei's third-party CAs versus a private PCA hierarchy.
Re-request public certificates in CCM through its supported CAs, replicating each SAN/domain set; for private PKI, recreate the CA hierarchy in PCA and re-sign certs rather than importing GCP-issued private certs, since trust chains differ. Move deployment bindings manually from GCP load-balancer target proxies to Huawei ELB, WAF, CDN, or VOD using one-click deploy. Replace any GCP certificate-map selection logic with the corresponding Huawei service's SNI/host routing configuration.
Validate each cert's chain, SAN coverage, and handshake before shifting DNS traffic. Confirm CCM auto-update and expiration notifications cover renewed multi-year certs, and configure CTS audit plus KMS key protection for the new custody model. Coordinate DNS cut-over per certificate so that GCP-managed cert renewal flows stop before decommission, and monitor for OCSP/CRL and browser-trust differences introduced by the new CA roots.
GCP managed-cert issuance is included at no charge beyond load-balancer pricing; Huawei CCM public SSL certificates are one-time paid per 1-3 year validity, and private CAs are billed monthly per CA. Private certificate workload limits and CA hierarchy depth differ. Recalculate TCO across certificate count, validity, CA tier, and renewals, and confirm regional availability of the chosen CAs before production cut-over, since RSA/ECC/SAN coverage and quota limits are not feature-identical.
Huawei Cloud
Huawei equivalent service
Shortname: CCM
General function: Certificate Security
Certificate lifecycle and management service.
Keywords: certificate, tls, pki