Use the Certificate Enrollment for ChromeOS extension

As an administrator you can use the Certificate Enrollment for ChromeOS extension to enable a user to get a user or device certificate either manually or automatically. You can also set up the automatic renewal of existing certificates that are expiring.

Before using the extension, ensure that users have access, and that the extension and associated managed policy are properly configured. For more help with setting up the extension, see the Extension deployment guide section.

Certificate request types

There are two types of certificate requests; user certificate requests and device certificate requests.

  • User certificate requests result in a certificate being issued for the specific user sending the request, not the overall device. User certificates are only valid for the user logged into that machine, not any other users who may also use the machine.
  • Device certificate requests result in a certificate being issued for the overall device sending the request, not just the user sending the request. Device certificates are valid for all users belonging to the same organization on the machine, which is typically necessary for devices being used in managed guest session or kiosk mode.

Certificate provisioning without user-entered credentials

You can configure the certificate enrollment extension to automatically provision or renew a certificate without requiring a user to manually enter credentials

When you configure one of the new provisioning or renewal options, the extension automatically detects if a certificate is not already provisioned on a device or if it is expiring soon, triggering a notification asking the user to get or renew a certificate. The user must click on the notification, and the extension starts the process of getting or renewing the certificate. For details, see the Extension deployment guide section.

Certificate provisioning with user-entered credentials

You can configure the certificate enrollment extension to let users manually provision a certificate

Primary user flows

User flows in the extension are broken down into primary and secondary categories. A primary user flow, described in this section, is something a user should typically expect to encounter.

Secondary user flows

Secondary user flows, described below, should occur only rarely.

Extension deployment guide

Applies to managed Chromebooks only.

As an administrator, you can let Chromebook users access your organization’s protected networks and internal resources that require a certificate for authentication. Remotely install and configure the Certificate Enrollment for ChromeOS extension so that your users can request user or system certificates on Chromebooks.

Alternatively, you can set up automated certificate provisioning using Kerberos authentication for user or device certificates or hosted service account authentication for device certificates. You can also set the extension to renew existing certificates without additional authentication using key-based renewal.

The extension also lets you scale your rollout of ChromeOS devices by automating the Microsoft Active Directory certificate enrollment process through the Google Admin console.

Before you begin

To let users request digital certificates, you need:

  • Microsoft Windows Server 2008 R2 or later
  • Microsoft Internet Information Services (IIS) 7.0 or later
  • Active Directory Certificate Services (ADCS) including:
    • Certificate enrollment service (CES)
    • Certificate enrollment policy (CEP)
    • A valid certificate associated to the ADCS website in IIS
    • A visible endpoint for CEP and CES

Disclaimer

This guide describes how Google products work with third-party products and the configurations that Google recommends. Google does not provide technical support for configuring third-party products. Google accepts no responsibility for third-party products. Go to the product's website for the latest configuration and support information.

Deploy the extension

Open all   |   Close all

Troubleshoot digital certificate requests

Applies to managed Chromebooks only.

Here's how to fix problems you might have when users request digital certificates.

Error messages in extension’s UI

Error messages in Chrome console logs

Google and related marks and logos are trademarks of Google LLC. All other company and product names are trademarks of the companies with which they are associated.

Was this helpful?

How can we improve it?
17306120926821758543
true
Search Help Center
true
true
true
true
true
410864
Search
Clear search
Close search
Main menu
false
false
false