Sign in to your Google Cloud account. If you're new to
Google Cloud,
create an account to evaluate how our products perform in
real-world scenarios. New customers also get $300 in free credits to
run, test, and deploy workloads.
In the Google Cloud console, on the project selector page,
select or create a Google Cloud project.
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-12。"],[[["\u003cp\u003eThis page provides instructions on how to prepare your environment for setting up Certificate Authority Service.\u003c/p\u003e\n"],["\u003cp\u003eIt outlines the process of enabling the CA Service API as part of the environment preparation.\u003c/p\u003e\n"],["\u003cp\u003eYou will need to acquire the \u003ccode\u003eroles/privateca.admin\u003c/code\u003e IAM role, or obtain the equivalent permissions through custom or other predefined roles.\u003c/p\u003e\n"],["\u003cp\u003eIt provides links to documentation about access control, managing roles, and getting started with CA Service.\u003c/p\u003e\n"]]],[],null,["# Prepare your environment for Certificate Authority Service\n==========================================================\n\nThis page shows you how to prepare your environment to set up\nCertificate Authority Service.\n\nEnable the CA Service API\n-------------------------\n\n- Sign in to your Google Cloud account. If you're new to Google Cloud, [create an account](https://console.cloud.google.com/freetrial) to evaluate how our products perform in real-world scenarios. New customers also get $300 in free credits to run, test, and deploy workloads.\n- In the Google Cloud console, on the project selector page,\n select or create a Google Cloud project.\n\n | **Note**: If you don't plan to keep the resources that you create in this procedure, create a project instead of selecting an existing project. After you finish these steps, you can delete the project, removing all resources associated with the project.\n\n [Go to project selector](https://console.cloud.google.com/projectselector2/home/dashboard)\n-\n [Verify that billing is enabled for your Google Cloud project](/billing/docs/how-to/verify-billing-enabled#confirm_billing_is_enabled_on_a_project).\n\n-\n\n\n Enable the Certificate Authority Service API.\n\n\n [Enable the API](https://console.cloud.google.com/flows/enableapi?apiid=privateca.googleapis.com)\n\n- In the Google Cloud console, on the project selector page,\n select or create a Google Cloud project.\n\n | **Note**: If you don't plan to keep the resources that you create in this procedure, create a project instead of selecting an existing project. After you finish these steps, you can delete the project, removing all resources associated with the project.\n\n [Go to project selector](https://console.cloud.google.com/projectselector2/home/dashboard)\n-\n [Verify that billing is enabled for your Google Cloud project](/billing/docs/how-to/verify-billing-enabled#confirm_billing_is_enabled_on_a_project).\n\n-\n\n\n Enable the Certificate Authority Service API.\n\n\n [Enable the API](https://console.cloud.google.com/flows/enableapi?apiid=privateca.googleapis.com)\n\n\u003cbr /\u003e\n\nConfigure roles and permissions\n-------------------------------\n\n\nTo get the permissions that\nyou need to set up CA Service,\n\nask your administrator to grant you the\n\n\n[CA Service Admin](/iam/docs/roles-permissions/privateca#privateca.admin) (`roles/privateca.admin`)\nIAM role on the project.\n\n\nFor more information about granting roles, see [Manage access to projects, folders, and organizations](/iam/docs/granting-changing-revoking-access).\n\n\nYou might also be able to get\nthe required permissions through [custom\nroles](/iam/docs/creating-custom-roles) or other [predefined\nroles](/iam/docs/roles-overview#predefined).\n\nFor information about granting roles to CA Service resources,\nsee [Access control with IAM](/certificate-authority-service/docs/access-control).\n\nWhat's next\n-----------\n\n- [Access control with IAM](/certificate-authority-service/docs/access-control).\n- Get started with [CA Service](/certificate-authority-service/docs/create-certificate)."]]