Certificate Authority Service 文档
Certificate Authority Service 是一项高可用性、可伸缩的 Google Cloud 服务,可帮助您简化、自动执行和自定义私有证书授权机构 (CA) 的部署、管理和安全维护。
获享 $300 免费赠金开始概念验证
-
体验 Gemini 2.0 Flash Thinking
-
免费使用热门产品(包括 AI API 和 BigQuery)的每月用量
-
不会自动收费,无需承诺
继续探索 20 多种提供“始终免费”用量的产品
使用适用于常见应用场景(包括 AI API、虚拟机、数据仓库等)的 20 多种免费产品。
培训
培训和教程
使用 Google Cloud 控制台签发证书
了解如何启用 Certificate Authority Service API、创建 CA 池、创建根 CA 以及从根 CA 颁发证书。
培训
培训和教程
管理政策控制措施
借助政策控制,您可以控制 CA 池可颁发的证书类型。本教程介绍了如何管理各种政策,以控制证书颁发和对 CA Service 资源的访问权限。
使用场景
使用场景
Hashicorp Vault CA 集成
Hashicorp Vault 通常用于在本地管理和存储 Secret。本主题介绍如何配置 Hashicorp Vault CA,使其充当将所有证书签发请求转发到 Certificate Authority Service 的代理。此集成可让当前部署的解决方案与 CA Service 原生搭配使用。
Hashicorp
本地
Secret
使用场景
使用场景
实现委派 OCSP 响应程序
使用 OCSP 提供证书吊销状态有很多好处。与可能非常大的证书吊销列表 (CRL) 相比,OCSP 具有响应时间更短、网络带宽要求更低等优势。本页面提供有关配置与 CA 服务搭配使用的委托 OCSP 响应者的信息。
OCSP
安全性
使用场景
使用场景
Terraform 是一种常用的开源工具,可让您使用其基础架构即代码范式创建和管理 Certificate Authority Service 资源。本指南提供有关将 Terraform 与 CA Service 搭配使用的信息。
Terraform
CA 服务 API
使用场景
使用场景
使用 Cert-Manager 管理证书生命周期
Cert-Manager 是一种 Kubernetes 加载项,用于自动管理和颁发来自各种颁发来源的 TLS 证书。您可以使用 Cert-Manager 管理使用 CA Service 创建的 CA 颁发的证书的生命周期。Cert-Manager 可确保证书有效,并在证书过期之前及时续订。
Cert-Manager
证书续订
使用场景
使用场景
将 Certificate Authority Service 与 Anthos Service Mesh 搭配使用
借助 CA Service,您可以从自己控制的证书授权机构 (CA) 请求工作负载身份证书。本文档介绍如何安装 Anthos Service Mesh 并将其与 Certificate Authority Service 搭配使用。
Anthos Service Mesh
使用场景
使用场景
使用 Envoy 设置 Traffic Director 服务安全
了解如何使用 Envoy 和 Certificate Authority Service 为 Traffic Director 设置服务安全。
Traffic Director
Envoy
使用场景
使用场景
使用无代理 gRPC 设置 Traffic Director 服务安全
了解如何使用无代理 gRPC 和 Certificate Authority Service 为 Traffic Director 设置服务安全。
Traffic Director
无代理 gRPC
使用场景
使用场景
如何使用 Certificate Authority Service 部署安全可靠的 PKI
本白皮书为组织使用 CA 服务提供了安全和架构方面的建议。本文档介绍了保护和部署 PKI 的关键概念,并针对配置 CA 服务以确保高运营可用性提供了具体建议。
PKI 设计
使用场景
使用场景
使用 Certificate Authority Service 调节证书管理
本白皮书介绍了 CA Service 如何解决组织在快速变化且互联的数字世界中使用数字证书时面临的挑战。
物联网
云计算
使用场景
使用场景
Certificate Authority Service 最佳实践
本主题介绍了更有效地使用 CA 服务的最佳实践。
访问权限控制
签名密钥
CA Service 层级
代码示例
代码示例
适用于 Go 的 Certificate Authority Service 客户端
使用 Go 惯用客户端的 Certificate Authority Service 示例。
代码示例
代码示例
适用于 Java 的 Certificate Authority Service 客户端
使用 Certificate Authority Service 的惯用 Java 客户端的示例。
代码示例
代码示例
适用于 Python 的 Certificate Authority Service 客户端
使用 Certificate Authority Service 的 Python 惯用客户端的示例。
如未另行说明,那么本页面中的内容已根据知识共享署名 4.0 许可获得了许可,并且代码示例已根据 Apache 2.0 许可获得了许可。有关详情,请参阅 Google 开发者网站政策。Java 是 Oracle 和/或其关联公司的注册商标。
最后更新时间 (UTC):2025-08-12。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-12。"],[[["\u003cp\u003eCertificate Authority Service is a Google Cloud service that simplifies and automates the management and security of private certificate authorities.\u003c/p\u003e\n"],["\u003cp\u003eThe documentation offers guides on various aspects, including creating CA pools, root CAs, subordinate CAs, and certificate templates, as well as configuring IAM policies.\u003c/p\u003e\n"],["\u003cp\u003eReference materials are available for authentication, RPC/REST APIs, gcloud commands, gRPC, certificate profiles, and RFC compliance.\u003c/p\u003e\n"],["\u003cp\u003eThe resources section contains information such as pricing, quotas, locations, release notes, known limitations, and the service level agreement.\u003c/p\u003e\n"],["\u003cp\u003eThere are various use cases and whitepapers detailed, including integrations with Hashicorp Vault, Terraform, and Cert-Manager, along with best practices, security recommendations, and code samples.\u003c/p\u003e\n"]]],[],null,["# Certificate Authority Service documentation\n===========================================\n\n[Read product documentation](/certificate-authority-service/docs/ca-service-overview)\nCertificate Authority Service is a highly available and scalable Google Cloud service that\nenables you to simplify, automate, and customize the deployment, management,\nand security of private certificate authorities (CA).\n[Get started for free](https://console.cloud.google.com/freetrial) \n\n#### Start your proof of concept with $300 in free credit\n\n- Get access to Gemini 2.0 Flash Thinking\n- Free monthly usage of popular products, including AI APIs and BigQuery\n- No automatic charges, no commitment \n[View free product offers](/free/docs/free-cloud-features#free-tier) \n\n#### Keep exploring with 20+ always-free products\n\n\nAccess 20+ free products for common use cases, including AI APIs, VMs, data warehouses,\nand more.\n\nDocumentation resources\n-----------------------\n\nFind quickstarts and guides, review key references, and get help with common issues. \nformat_list_numbered\n\n### Guides\n\n-\n\n [Overview](/certificate-authority-service/docs/ca-service-overview)\n\n-\n\n [Configure IAM policies](/certificate-authority-service/docs/configuring-iam)\n\n-\n\n [Create a CA pool](/certificate-authority-service/docs/creating-ca-pool)\n\n-\n\n [Create a root CA](/certificate-authority-service/docs/creating-certificate-authorities)\n\n-\n\n [Create a subordinate CA](/certificate-authority-service/docs/create-subordinate-ca)\n\n-\n\n [Create a certificate template](/certificate-authority-service/docs/creating-certificate-template)\n\n-\n\n [Overview of policy controls](/certificate-authority-service/docs/policy-controls)\n\n-\n\n [Create a certificate request](/certificate-authority-service/docs/requesting-certificates)\n\n-\n\n [Increase certificate creation throughput using CA pools](/certificate-authority-service/docs/higher-qps)\n\nfind_in_page\n\n### Reference\n\n-\n\n [Authenticate to CA Service](/certificate-authority-service/docs/authentication)\n\n-\n\n [RPC APIs](/certificate-authority-service/docs/reference/rpc)\n\n-\n\n [REST APIs](/certificate-authority-service/docs/reference/rest)\n\n-\n\n [gcloud privateca commands](/sdk/gcloud/reference/privateca)\n\n-\n\n [Using gRPC](/certificate-authority-service/docs/using-grpc)\n\n-\n\n [Certificate profiles](/certificate-authority-service/docs/certificate-profile)\n\n-\n\n [RFC compliance](/certificate-authority-service/docs/rfc-compliance)\n\ninfo\n\n### Resources\n\n-\n\n [Security and compliance](/certificate-authority-service/docs/certificate-authority-compliance)\n\n-\n\n [Pricing](/certificate-authority-service/pricing)\n\n-\n\n [Quotas and limits](/certificate-authority-service/quotas)\n\n-\n\n [Locations](/certificate-authority-service/docs/locations)\n\n-\n\n [Release notes](/certificate-authority-service/docs/release-notes)\n\n-\n\n [Known limitations](/certificate-authority-service/docs/known-limitations)\n\n-\n\n [Service Level Agreement](/certificate-authority-service/sla)\n\n-\n\n [Getting support](/certificate-authority-service/docs/getting-support)\n\nRelated resources\n-----------------\n\nTraining and tutorials \nUse cases \nCode samples \nExplore self-paced training, use cases, reference architectures, and code samples with examples of how to use and connect Google Cloud services. Training \nTraining and tutorials\n\n### Issue a certificate using the Google Cloud console\n\n\nLearn how to enable the Certificate Authority Service API, create a CA pool, create a root CA, and issue certificates from the root CA.\n\n\n[Learn more](/certificate-authority-service/docs/create-certificate) \nTraining \nTraining and tutorials\n\n### Manage policy controls\n\n\nPolicy controls let you control the type of certificates that your CA pool can issue. This tutorial explains how you can manage various policies to control certificate issuance and access to CA Service resources.\n\n\n[Learn more](/certificate-authority-service/docs/tutorials/manage-policy-controls) \nUse case \nUse cases\n\n### Hashicorp Vault CA integration\n\n\nHashicorp Vault is commonly used for managing and storing secrets on-premises. This topic describes how Hashicorp Vault CA can be configured to act as a proxy that forwards all certificate issuance requests to Certificate Authority Service. This integration allows a currently deployed solution to natively work with CA Service.\n\nHashicorp On-premises Secrets\n\n\u003cbr /\u003e\n\n[Learn more](/certificate-authority-service/docs/hashicorp-integration) \nUse case \nUse cases\n\n### Implementing a delegated OCSP responder\n\n\nUsing OCSP to provide the certificate revocation status can have many benefits. These benefits include quicker response time and smaller requirement for network bandwidth, as compared to Certificate Revocation Lists (CRLs), which can get very large. This page provides information about configuring a delegated OCSP responder that works with CA Service.\n\nOCSP Security\n\n\u003cbr /\u003e\n\n[Learn more](/certificate-authority-service/docs/ocsp-support) \nUse case \nUse cases\n\n### Using Terraform\n\n\nTerraform is a popular open source tool that lets you create and manage your Certificate Authority Service resources using its infrastructure-as-code paradigm. This guide provides information about using Terraform with CA Service.\n\nTerraform CA Service APIs\n\n\u003cbr /\u003e\n\n[Learn more](/certificate-authority-service/docs/using-terraform) \nUse case \nUse cases\n\n### Manage certificate lifecycle using Cert-Manager\n\n\nCert-Manager is a Kubernetes add-on to automate the management and issuance of TLS certificates from various issuing sources. You can use Cert-Manager to manage the lifecycle of certificates issued by CAs that are created using CA Service. Cert-Manager ensures certificates are valid and duly renewed before they expire.\n\nCert-Manager Certificate renewal\n\n\u003cbr /\u003e\n\n[Learn more](/certificate-authority-service/docs/cert-manager) \nUse case \nUse cases\n\n### Use Certificate Authority Service with Anthos Service Mesh\n\n\nCA Service lets you request workload identity certificates from a certificate authority (CA) that you control. This document explains how you can install Anthos Service Mesh and use Certificate Authority Service with it.\n\nAnthos Service Mesh\n\n\u003cbr /\u003e\n\n[Learn more](/service-mesh/docs/unified-install/install-anthos-service-mesh#install_ca_service) \nUse case \nUse cases\n\n### Set up Traffic Director service security with Envoy\n\n\nLearn how you can set up service security for Traffic Director with Envoy and Certificate Authority Service.\n\nTraffic Director Envoy\n\n\u003cbr /\u003e\n\n[Learn more](/traffic-director/docs/security-envoy-setup) \nUse case \nUse cases\n\n### Set up Traffic Director service security with proxyless gRPC\n\n\nLearn how you can set up service security for Traffic Director with proxyless gRPC and Certificate Authority Service.\n\nTraffic Director proxyless gRPC\n\n\u003cbr /\u003e\n\n[Learn more](/traffic-director/docs/security-proxyless-setup) \nUse case \nUse cases\n\n### How to deploy a secure and reliable PKI with Certificate Authority Service\n\n\nThis whitepaper provides security and architectural recommendations to organizations for the use of CA Service. It describes critical concepts to securing and deploying a PKI and provides specific recommendations for configuring CA Service to ensure high operational availability.\n\nPKI design\n\n\u003cbr /\u003e\n\n[Learn more](https://services.google.com/fh/files/misc/deploying_public_key_infrastructure_with_cas.pdf) \nUse case \nUse cases\n\n### Scaling certificate management with Certificate Authority Service\n\n\nThis whitepaper explains how CA Service addresses the challenges organizations face as they use digital certificates in a fast-changing and interconnected digital world.\n\nIoT Cloud computing\n\n\u003cbr /\u003e\n\n[Learn more](https://services.google.com/fh/files/misc/scaling_certificate_management_cas.pdf) \nUse case \nUse cases\n\n### Best practices for Certificate Authority Service\n\n\nThis topic provides the best practices to use CA Service more effectively.\n\nAccess control Signing keys CA Service tiers\n\n\u003cbr /\u003e\n\n[Learn more](/certificate-authority-service/docs/best-practices) \nCode sample \nCode Samples\n\n### Certificate Authority Service Client for Go\n\n\nSamples that use the Go idiomatic client for Certificate Authority Service.\n\n\n[Open GitHub\narrow_forward](https://github.com/GoogleCloudPlatform/golang-samples/tree/main/privateca) \nCode sample \nCode Samples\n\n### Certificate Authority Service Client for Java\n\n\nSamples that use the Java idiomatic client for Certificate Authority Service.\n\n\n[Open GitHub\narrow_forward](https://github.com/GoogleCloudPlatform/java-docs-samples/tree/main/privateca/snippets) \nCode sample \nCode Samples\n\n### Certificate Authority Service Client for Python\n\n\nSamples that use the Python idiomatic client for Certificate Authority Service.\n\n\n[Open GitHub\narrow_forward](https://github.com/GoogleCloudPlatform/python-docs-samples/tree/main/privateca/snippets)\n\nRelated videos\n--------------"]]