Managing CAS DevOps tier certificate

36 Views Asked by At

I have a question about Certificate Authority Service in Google Cloud Platform. Background: I have a fluent-bit agent running in my on-prem kubernetes cluster. Fluent-bit sends logs to GCP cloud logging. TLS verification is on. I created DevOps tier CA in CAS and then requested a ceritificate. My question is why option "Publish certificate revocation lists (CRLs) to the Cloud Storage bucket" is disabled for DevOps tier certs? Because of that certificates are not listed in certificate manager. What if I would like to revoke the certificate? There is no control over DevOps tier certs. My second question is what tier should be used in described case? DevOps (short-lived certificates) or Enterprise (longer-lived certificates)?

0

There are 0 best solutions below