# Overview Type of document: Reference Product: F5 Application Delivery Service for Google Cloud > Reference for supported SSL/TLS certificate types and how to add them to an F5 Application Delivery Service for Google Cloud deployment. --- Use F5 Application Delivery Service for Google Cloud to secure traffic by adding SSL/TLS certificates to a deployment. ## Supported certificate types and formats NGINX supports the following certificate formats: - PEM format certificates. You can upload these certificates as text, as files, or as secrets from [Secret Manager](https://docs.cloud.google.com/secret-manager/docs/overview). Encrypt your certificates, keys, and PEM files using one of these standards: - RSA - ECC/ECDSA - ML-DSA (post-quantum) **Note:** When you upload an ML-DSA private key using the F5 ADS Console, use the seed-only key format. If you store your ML-DSA key in Google Secret Manager, you can use either the seed-only or seed-priv format. See [Enable post-quantum cryptography](/f5ads/google/quickstart/pqc.md) for configuration guidance. ## Add SSL/TLS certificates F5 ADS for Google Cloud supports two ways to manage your certificates and keys securely: **F5 ADS Console**: Manage certificates alongside the NGINX configurations that reference them. See [Add certificates using the F5 ADS Console](/f5ads/google/deploy/ssl-tls-certificates/ssl-tls-certificates-console.md). **Google Secret Manager**: Fetch secrets directly from [Secret Manager](https://docs.cloud.google.com/secret-manager/docs/overview), keeping credentials within Google Cloud. See [Add certificates from Secret Manager](/f5ads/google/deploy/ssl-tls-certificates/ssl-tls-certificates-secret-manager.md). ## Certificate rotation F5 ADS for Google Cloud supports automatic and manual rotation for Secret Manager certificates: **Automatic rotation**: Let F5 ADS for Google Cloud pick up new certificate versions automatically with no configuration changes needed. See [Rotate a Secret Manager certificate (automatic)](/f5ads/google/deploy/ssl-tls-certificates/ssl-tls-certificates-secret-manager.md#rotate-a-secret-manager-certificate-automatic). **Manual rotation**: When you need to update certificates immediately, use **Reapply Configuration** in the console to refetch secrets right away. See [Rotate a Secret Manager certificate (manual)](/f5ads/google/deploy/ssl-tls-certificates/ssl-tls-certificates-secret-manager.md#rotate-a-secret-manager-certificate-manual).