---
title: "POST /projects/{project}/global/sslCertificates"
method: POST
path: "/projects/{project}/global/sslCertificates"
tags: ["sslCertificates"]
---

# POST /projects/{project}/global/sslCertificates

`POST /projects/{project}/global/sslCertificates`

Creates a SslCertificate resource in the specified project using the data
included in the request.

## Path parameters

- `project` string, required

## Query parameters

- `requestId` string

## Request body

- SslCertificate — Represents an SSL certificate resource. Google Compute Engine has two SSL certificate resources: * [Global](/compute/docs/reference/rest/v1/sslCertificates) * [Regional](/compute/docs/reference/rest/v1/regionSslCertificates) The global SSL certificates (sslCertificates) are used by: - Global external Application Load Balancers - Classic Application Load Balancers - Proxy Network Load Balancers (with target SSL proxies) The regional SSL certificates (regionSslCertificates) are used by: - Regional external Application Load Balancers - Regional internal Application Load Balancers Optionally, certificate file contents that you upload can contain a set of up to five PEM-encoded certificates. The API call creates an object (sslCertificate) that holds this data. You can use SSL keys and certificates to secure connections to a load balancer. For more information, read Creating and using SSL certificates,SSL certificates quotas and limits, and Troubleshooting SSL certificates.
  - `selfLink` string — [Output only] Server-defined URL for the resource.
  - `selfManaged` SslCertificateSelfManagedSslCertificate — Configuration and status of a self-managed SSL certificate.
    - `certificate` string — A local certificate file. The certificate must be in PEM format. The certificate chain must be no greater than 5 certs long. The chain must include at least one intermediate cert.
    - `privateKey` string — A write-only private key in PEM format. Only insert requests will include this field.
  - `type` 'MANAGED' | 'SELF_MANAGED' | 'TYPE_UNSPECIFIED' — (Optional) Specifies the type of SSL certificate, either "SELF_MANAGED" or "MANAGED". If not specified, the certificate is self-managed and the fieldscertificate and private_key are used.
  - `subjectAlternativeNames` string[] — Output only. [Output Only] Domains associated with the certificate via Subject Alternative Name.
  - `id` string, uint64 — [Output Only] The unique identifier for the resource. This identifier is defined by the server.
  - `certificate` string — A value read into memory from a certificate file. The certificate file must be in PEM format. The certificate chain must be no greater than 5 certs long. The chain must include at least one intermediate cert.
  - `managed` SslCertificateManagedSslCertificate — Configuration and status of a managed SSL certificate.
    - `domains` string[] — The domains for which a managed SSL certificate will be generated. Each Google-managed SSL certificate supports up to the [maximum number of domains per Google-managed SSL certificate](/load-balancing/docs/quotas#ssl_certificates).
    - `domainStatus` object — Output only. [Output only] Detailed statuses of the domains specified for managed certificate resource.
    - `status` 'ACTIVE' | 'MANAGED_CERTIFICATE_STATUS_UNSPECIFIED' | 'PROVISIONING' | 'PROVISIONING_FAILED' | 'PROVISIONING_FAILED_PERMANENTLY' | 'RENEWAL_FAILED' — Output only. [Output only] Status of the managed certificate resource.
  - `privateKey` string — A value read into memory from a write-only private key file. The private key file must be in PEM format. For security, only insert requests include this field.
  - `expireTime` string — Output only. [Output Only] Expire time of the certificate. RFC3339
  - `kind` string — Output only. [Output Only] Type of the resource. Alwayscompute#sslCertificate for SSL certificates.
  - `name` string — Name of the resource. Provided by the client when the resource is created. The name must be 1-63 characters long, and comply withRFC1035. Specifically, the name must be 1-63 characters long and match the regular expression `[a-z]([-a-z0-9]*[a-z0-9])?` which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash.
  - `creationTimestamp` string — [Output Only] Creation timestamp inRFC3339 text format.
  - `description` string — An optional description of this resource. Provide this property when you create the resource.
  - `region` string — Output only. [Output Only] URL of the region where the regional SSL Certificate resides. This field is not applicable to global SSL Certificate.

## Response `200`

Successful response

---

[API](https://skmtc.net/google/apis/compute.md) · [All operations](https://skmtc.net/google/apis/compute/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/google/compute/revisions/6120ed8969d4/schema)
