Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Batasan umum
Halaman ini mendokumentasikan batasan umum Certificate Authority Service.
Dukungan pencabutan
Pencabutan sertifikat hanya didukung melalui Daftar Pencabutan Sertifikat
(CRL). Protokol Status Sertifikat Online (OCSP) tidak didukung oleh Layanan CA, tetapi Anda dapat menerapkan dan menjalankan responden OCSP yang didelegasikan.
Untuk informasi selengkapnya tentang cara menerapkan OCSP responder, lihat Dukungan OCSP.
Kunci yang dibuat klien
CLI Google Cloud dan antarmuka konsol Google Cloud mendukung
pembuatan pasangan kunci asimetris secara otomatis saat menerbitkan sertifikat untuk
kemudahan tambahan. Kunci yang dibuat menggunakan Google Cloud CLI dibatasi hingga RSA-2048, sedangkan kunci yang dibuat menggunakan konsol Google Cloud mendukung lebih banyak algoritma.
Subjek sertifikat
Layanan CA hanya mendukung jenis atribut berikut dalam subjek sertifikat:
- Nama Umum (CN)
- Kode Negara (C)
- Organisasi (O)
- Unit Organisasi (OU)
- Lokalitas (L)
- Provinsi (ST)
- Street Address
- Postal Code
Batasan ini berlaku untuk kolom subjek dalam sertifikat CA dan
sertifikat entitas akhir. Setiap jenis atribut ini hanya dibatasi untuk satu
nilai.
Untuk informasi selengkapnya, lihat pesan Subjek dalam dokumentasi REST API.
Langkah berikutnya
Kecuali dinyatakan lain, konten di halaman ini dilisensikan berdasarkan Lisensi Creative Commons Attribution 4.0, sedangkan contoh kode dilisensikan berdasarkan Lisensi Apache 2.0. Untuk mengetahui informasi selengkapnya, lihat Kebijakan Situs Google Developers. Java adalah merek dagang terdaftar dari Oracle dan/atau afiliasinya.
Terakhir diperbarui pada 2025-08-12 UTC.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-12 UTC."],[[["\u003cp\u003eCertificate revocation is only supported through Certificate Revocation Lists (CRLs), with Online Certificate Status Protocol (OCSP) not directly supported but able to be implemented separately.\u003c/p\u003e\n"],["\u003cp\u003eClient-generated keys through Google Cloud CLI are limited to RSA-2048, while the Google Cloud console supports a wider range of algorithms.\u003c/p\u003e\n"],["\u003cp\u003eThe Certificate Authority Service only supports a restricted set of attribute types within the certificate subject, including Common Name, Country Code, Organization, Organizational Unit, Locality, Province, Street Address, and Postal Code, each limited to a single value.\u003c/p\u003e\n"],["\u003cp\u003eThe certificate subject limitations apply to both CA certificates and end-entity certificates.\u003c/p\u003e\n"]]],[],null,["# Known limitations\n=================\n\nThis page documents the known limitations of Certificate Authority Service.\n\nRevocation support\n------------------\n\nCertificate revocation is only supported through Certificate Revocation Lists\n(CRLs). Online Certificate Status Protocol (OCSP) isn't supported by CA Service, but you can implement and run a delegated OCSP responder.\n\nFor more information on implementing an OCSP responder, see [OCSP support](/certificate-authority-service/docs/ocsp-support).\n\nClient-generated keys\n---------------------\n\nThe Google Cloud CLI and Google Cloud console surfaces support\nautomatically generating an asymmetric key-pair when issuing certificates for\nadded convenience. Keys generated using Google Cloud CLI are limited to RSA-2048,\nwhile keys generated using Google Cloud console support a wider selection of\nalgorithms.\n\nCertificate subject\n-------------------\n\nCA Service only supports the following attribute types in the subject of a certificate:\n\n- Common Name (CN)\n- Country Code (C)\n- Organization (O)\n- Organizational Unit (OU)\n- Locality (L)\n- Province (ST)\n- Street Address\n- Postal Code\n\nThis limitation applies to the subject field in both CA certificates and\nend-entity certificates. Each of these attribute types is limited to only one\nvalue.\n\nFor more information, see the [Subject](/certificate-authority-service/docs/reference/rest/v1/Subject) message in the REST API documentation.\n\nWhat's next\n-----------\n\n- Read answers to the [frequently asked questions](/certificate-authority-service/docs/faqs).\n- Learn how to [troubleshoot common issues encountered in CA Service](/certificate-authority-service/docs/troubleshooting)."]]