Comparison route

Single service comparison

Back to main page

Certificate Security

Certificate Manager

GCP Certificate Manager provisions and manages TLS/SSL certificates for Google Cloud Load Balancing, using certificate maps to bind certificates to target proxies. It supports Google-managed certificates (DNS or load-balancer authorization), self-managed certificates, and Public CA-issued certificates, with automated renewal and rotation. A 2nd-generation layer adds a certificate directory, inventory, and monitoring. It is purpose-built for load-balancer-attached TLS, not an enterprise-wide PKI store.

Google Cloud logo

Google Cloud

Service information

Certificate Manager iconCertificate Manager

Shortname: Certificate Manager

Huawei equivalent shortnames: CCM

Keywords: certificate, tls, pki, security

Differences vs Huawei

GCP Certificate Manager uses certificate maps that bind one or more certificates to external/global load balancer target proxies, with selection logic per SNI hostname. Huawei CCM treats certificates as a lifecycle repository and pushes them via one-click deployment to WAF, ELB, CDN, and VOD rather than through a declarative map object. The two therefore expose different data models and control-plane APIs; you cannot lift a GCP certificate map into Huawei as-is.

GCP offers Google-managed certificates with automated DNS/LB authorization and renewal, plus Public CA integration, and delegates private PKI to the separate Certificate Authority Service. Huawei CCM bundles public SSL certificates (issued through third-party CAs such as DigiCert, GlobalSign, and GeoTrust) and Private CA (PCA) into one product, with auto-update of multi-year certs deployed to other services but manual application per issuance. Private PKI boundaries and automation hooks differ between the platforms.

GCP Certificate Manager (2nd gen) provides a certificate directory, inventory view, monitoring metrics, and Cloud Logging integration for cert health; integration is optimized for Google Cloud Load Balancing and Certificate Authority Service. Huawei CCM surfaces expiration notifications, Cloud Trace Service (CTS) audit, and KMS/HSM-backed key storage, integrating with Huawei WAF, ELB, CDN, VOD, and DEW. Operational observability, key custody, and the set of deploy targets are not equivalent and must be re-planned.

Migration to Huawei

Inventory every GCP certificate map, certificate scope (managed, self-managed, or Public CA), target load balancers, and SNI routing rules. Huawei CCM is the closest equivalent for public SSL lifecycle and private PKI (PCA), but neither CCM nor any Huawei migration service offers an automated import from GCP Certificate Manager. Plan a manual re-issuance and redeployment effort, and decide which certs reissue via Huawei's third-party CAs versus a private PCA hierarchy.

Re-request public certificates in CCM through its supported CAs, replicating each SAN/domain set; for private PKI, recreate the CA hierarchy in PCA and re-sign certs rather than importing GCP-issued private certs, since trust chains differ. Move deployment bindings manually from GCP load-balancer target proxies to Huawei ELB, WAF, CDN, or VOD using one-click deploy. Replace any GCP certificate-map selection logic with the corresponding Huawei service's SNI/host routing configuration.

Validate each cert's chain, SAN coverage, and handshake before shifting DNS traffic. Confirm CCM auto-update and expiration notifications cover renewed multi-year certs, and configure CTS audit plus KMS key protection for the new custody model. Coordinate DNS cut-over per certificate so that GCP-managed cert renewal flows stop before decommission, and monitor for OCSP/CRL and browser-trust differences introduced by the new CA roots.

GCP managed-cert issuance is included at no charge beyond load-balancer pricing; Huawei CCM public SSL certificates are one-time paid per 1-3 year validity, and private CAs are billed monthly per CA. Private certificate workload limits and CA hierarchy depth differ. Recalculate TCO across certificate count, validity, CA tier, and renewals, and confirm regional availability of the chosen CAs before production cut-over, since RSA/ECC/SAN coverage and quota limits are not feature-identical.

Huawei Cloud logo

Huawei Cloud

Huawei equivalent service

Cloud Certificate & Manager iconCloud Certificate & Manager

Shortname: CCM

General function: Certificate Security

Certificate lifecycle and management service.

Keywords: certificate, tls, pki