Onboard Chromebooks with certificates using Google Workspace, Google Cloud, and SCEP
In this topic, you will learn how to deploy Portnox™ Cloud certificates to Chromebook (ChromeOS) devices using Google Workspace, Google Cloud, and SCEP.
Before you can deploy Portnox Cloud certificates via Google Workspace, Google Cloud, and SCEP, you must complete the following steps:
-
Prepare a physical or virtual Windows machine that can access Portnox Cloud SCEP services (has access to the Internet via HTTP), where you will install the Google Cloud Certificate Connector. This machine may run a non-server distribution of the Windows operating system such as Windows 10 or Windows 11, or the Windows Server operating system.
-
If you plan to use device-based certificates, make sure your Chromebooks are running ChromeOS 138 or later.
-
Make sure that the Google administrator account that you will use for this configuration has the Shared Device Settings privileges.
-
Make sure your organization has an active Chrome Enterprise Upgrade (or Chrome Education Upgrade) license.
-
Have access to a Google Cloud project – either an existing one or a new one you create for this purpose – and administrative (Owner or equivalent) permissions on it. A billing account must be linked to the project; this does not mean you will be charged, but Google requires it to enable APIs. This process generates a small amount of traffic and stays well within Google’s free monthly usage tier even at high volume.
Turn on the Portnox Cloud SCEP services
In this section, you will configure Portnox™ Cloud to provide SCEP services to your devices.
If you have previously turned on the Portnox Cloud SCEP services, skip to the later steps.
Portnox Cloud SCEP services let devices contact the Cloud SCEP server and get a unique certificate for the device or for the specific user of the device.
Download the root CA certificate from Portnox Cloud
In this section, you will download the Portnox™ Cloud root CA certificate from the Cloud portal and convert it to the Base-64 encoded X.509 format using a Windows computer.
You need the root CA certificate so that your managed devices can verify the validity of Cloud RADIUS servers, which have certificates signed by this root CA certificate. If the root CA certificate is not distributed to managed devices, some devices may show a security warning each time that the user connects to networks managed by Portnox Cloud.
openssl x509 -inform der -in input_file.cer -outform pem -out output_file.cer.Optional: Hand over information from the Portnox Cloud team to the Google team
In this section, you will learn what information was collected in previous steps from Portnox Cloud, which is needed to configure Google Cloud, the connector, and Google Workspace to work with Portnox Cloud.
If different people are responsible for managing Portnox Cloud and Google Cloud/Google Workspace, here is the information you need to hand over:
- The Portnox Cloud SCEP URL. For example, https://scep.portnox.com/b2973887-1274-45a4-91d0-4a342a861c76.
- The Portnox Cloud SCEP password.
- The root CA certificate file in the Base-64 encoded X.509 format. For example, rootCertificate.cer.
Configure the Google Cloud project
In this section, you will create or select a Google Cloud project, enable the Chrome Management API, create a Pub/Sub topic, and create a service account for the connector.
Install and configure the Google Cloud Certificate Connector
In this section, you will download and install the Google Cloud Certificate Connector on a Windows machine, and configure it to communicate with your Google Cloud project and the Portnox™ Cloud SCEP server.
Configure Google Admin
In this section, you will create a SCEP Certificate Authority connection and a certificate provisioning profile in the Google Admin console.
Optional: Turn on Google Verified Access
In this section, you will enable Google Verified Access to let network services cryptographically verify that connecting Chromebooks are genuine and policy-compliant.
Google Verified Access lets a network service cryptographically confirm that a connecting Chromebook is genuine, enrolled, and running an unmodified, policy-compliant version of ChromeOS. Setting it up involves three parts: enabling an API in your Google Cloud project, configuring a policy in Google Admin, and turning on a matching option in your Portnox Cloud Google Workspace integration.
Result: Portnox Cloud can now validate Google Verified Access policy attributes against Google Workspace during device authentication for ChromeOS risk assessment policies.
Create a profile for the root CA certificate
In this section, you will create a profile in Google Workspace for the downloaded Portnox™ Cloud root CA certificate.
Result: You created a profile for the Portnox Cloud root CA certificate.

Create a Wi-Fi profile
In this section, you will create a Wi-Fi profile in Google Workspace for Chromebooks managed by Portnox™ Cloud.
Result: You created a Wi-Fi profile for the network managed by Portnox Cloud.

Optional: Disable the legacy Secure SCEP configuration
In this section, you will remove the legacy Secure SCEP profile from Google Workspace, so that Chromebooks stop using the older, poll-based certificate enrollment method before you configure the new process.
Result: Devices in the selected organizational unit will no longer enroll for certificates using the legacy Secure SCEP method.
Test your configuration on a managed Chromebook
In this section, you will test the configuration you created by connecting a Chromebook to the network managed by Portnox™ Cloud.
Result: The Chromebook connects automatically, using the certificate issued through Google Cloud, Google Workspace, and Portnox Cloud SCEP.
If the Chromebook does not connect, check the following:
- Open chrome://certificate-manager, click on the Your certificates tab, and confirm a certificate was issued.
- On the Windows server, check that the Google Cloud Certificate Connector service is running, and check its logs in Event Viewer () for errors.






























































