Support · Requirements · Installation · License · Related Integrations
The Google Cloud DNS Plugin is a Keyfactor Domain Validator implementation that manages DNS records in Google Cloud DNS managed zones. It plugs into the Keyfactor AnyCA Gateway as an IDomainValidator and is invoked automatically during certificate enrollment when DNS-based domain control validation is required.
The DLL ships two validator types:
| Validator class | Validation type | Record published | Use case |
|---|---|---|---|
GoogleDomainValidator |
dns-01 |
TXT | ACME DNS-01 challenges |
GoogleCnameDomainValidator |
cname |
CNAME | CNAME-based DCV (e.g. CSC Global, SSL Store) |
When configuring a Domain Validation Configuration in the gateway UI, pick the validator type that matches the CA's requirement — TXT/dns-01 for ACME, CNAME/cname for CAs that validate via CNAME. Both share the same Google Cloud credentials and configuration fields.
The plugin uses the Google Cloud DNS API via the official Google.Apis.Dns.v1 SDK. Records are applied through the Changes API (a delete of the prior record set plus an add of the new one). For TXT staging, existing values at the same name are preserved and the new value is appended, so co-existing ACME challenges (a wildcard and the apex domain both producing _acme-challenge TXT values) coexist. For CNAME staging, the record set is replaced since a CNAME is singular per name by DNS rules. On cleanup, the record set for the managed type/name is removed (for TXT, if a specific value is supplied only that value is removed and any co-existing values are preserved).
The owning zone for a given FQDN is resolved by listing the Cloud DNS managed zones in the configured project and selecting the one whose dnsName is the longest matching suffix of the record name.
- Automated DNS TXT record creation and deletion in Google Cloud DNS
- Keyfactor AnyCA Gateway REST 26.2 or later (DNS validation support was added in AnyCA Gateway 26.2)
- A gateway product that supports DNS-01 domain validation (ACME REST Gateway, DigiCert, Sectigo, etc.)
- Keyfactor AnyCA Gateway REST 26.2 or later (DNS validation support was added in AnyCA Gateway 26.2)
- A gateway product that supports DNS-based domain validation (ACME REST Gateway, DigiCert, Sectigo, SSL Store, etc.)
- A Google Cloud project with Cloud DNS enabled and one or more managed zones for the domains being validated.
- A principal the plugin can authenticate as, with permission to read zones and write record sets. The built-in role DNS Administrator (
roles/dns.admin) is sufficient; a custom role needs at leastdns.managedZones.list,dns.resourceRecordSets.*, anddns.changes.create. - Credentials, provided by one of (in resolution order):
- Service Account key JSON (
Google_ServiceAccountKeyJson) — recommended for gateways not running on GCP. - Service Account key file (
Google_ServiceAccountKeyPath) — a path to the JSON key on the gateway host. - Application Default Credentials / Workload Identity — used automatically when neither key is supplied (ideal when the gateway runs on GCP).
- Service Account key JSON (
| Field | Required | Description |
|---|---|---|
Google_ProjectId |
Yes | Google Cloud project ID that contains the Cloud DNS managed zones. |
Google_ServiceAccountKeyJson |
No | Service Account key as JSON. Stored as a secret. Leave empty to use a key file or Application Default Credentials. |
Google_ServiceAccountKeyPath |
No | Path to a Service Account JSON key file on the gateway host. Used only when the JSON key is empty. |
- The plugin sets the record TTL to 60 seconds.
- Zones are discovered from the configured project only; a record whose domain is not covered by a managed zone in that project fails with
No Google Cloud DNS managed zone found. - Each validator type manages only its own record type:
GoogleDomainValidatorreads/writesTXT,GoogleCnameDomainValidatorreads/writesCNAME. Neither touches other record types. - Cloud DNS stores TXT rdata quoted; the plugin quotes values automatically and will not double-quote an already-quoted value.
- .NET 10.0 runtime (provided by the gateway server)
This plugin is installed alongside any Keyfactor gateway server that supports DNS-01 domain validation (ACME REST Gateway, DigiCert, Sectigo, etc.). The same DLL works with every supported gateway.
See the official Keyfactor AnyCA Gateway REST installation documentation for the authoritative install instructions: . The steps below are a general guide; defer to the official docs if they diverge.
Download the latest release from the Releases page.
On the server hosting your gateway, unzip the release and copy the contents of the net10.0 directory into the gateway's Extensions folder.
Windows (example path — substitute the gateway product folder for your install):
C:\Program Files\Keyfactor\<GatewayName>\AnyGatewayREST\net10.0\Extensions\
Linux:
/opt/keyfactor/<gateway-name>/AnyGatewayREST/net10.0/Extensions/
Replace <GatewayName> (or <gateway-name> on Linux) with the gateway you are installing into (e.g. AcmeGwDns, DigiCert, Sectigo).
Restart the AnyGatewayREST Windows service for the gateway you installed the plugin into so the Extensions folder is rescanned.
After installing the plugin DLL into the gateway's Extensions folder, configure a new DNS Provider entry in the AnyCA Gateway REST UI and select Google Cloud as the provider type. See the official Keyfactor AnyCA Gateway REST documentation for the canonical UI walkthrough: .
| Parameter | Description | Required | Example |
|---|---|---|---|
Google_ProjectId |
Google Cloud project ID that contains the Cloud DNS managed zones. | Yes | |
Google_ServiceAccountKeyJson |
Service Account key as JSON. Optional — leave empty to use a key file or Application Default Credentials / Workload Identity. Stored as a secret. | No | |
Google_ServiceAccountKeyPath |
Path to a Service Account JSON key file on the gateway host. Used only when the JSON key is not provided. Leave empty to use Application Default Credentials. | No | |
{
"Google_ProjectId": "",
"Google_ServiceAccountKeyJson": "",
"Google_ServiceAccountKeyPath": ""
}Once configured, the plugin automatically handles DNS validation during certificate enrollment and renewal:
- Record Creation: Plugin creates a DNS TXT record with the validation challenge
- Propagation Wait: Plugin waits for DNS propagation
- Verification: Plugin verifies the record exists on Google Cloud DNS nameservers
- Cleanup: Plugin deletes the validation record after successful validation
The plugin automatically discovers the appropriate DNS zone for a domain:
- For
www.example.com, searches for zones:www.example.com,example.com - For
sub.example.com, searches for zones:sub.example.com,example.com - For
*.example.com, searches for zones:example.com
- Authentication Failures: Verify Google Cloud DNS credentials are valid, not expired, and authorized for the target zone.
- Insufficient Permissions: Verify the account/role has the documented minimum permissions on the target DNS zone.
- Zone Not Found: Verify the target DNS zone exists in your Google Cloud DNS account and is reachable from the gateway server.
- DNS Propagation Timeouts: Check Google Cloud DNS service health; verify authoritative nameservers are responding.
Enable debug logging in the gateway's logging configuration:
{
"Logging": {
"LogLevel": {
"Keyfactor.Extensions.DomainValidator.Google": "Debug"
}
}
}The Google Cloud DNS Provider plugin is open source and there is no SLA. Keyfactor will address issues as resources become available. Keyfactor customers may request escalation by opening a support ticket through their Keyfactor representative.
To report a problem or suggest a new feature, use the Issues tab. If you want to contribute actual bug fixes or proposed enhancements, use the Pull requests tab.
Apache License 2.0, see LICENSE.
See all Keyfactor DNS Provider plugins.