Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Halaman ini memberikan ringkasan tentang cara menggunakan Pengelola Sertifikat untuk menyediakan sertifikat yang dikelola Google dan dikelola sendiri untuk Load Balancer Aplikasi dan Load Balancer Jaringan proxy.
Sebelum membaca halaman ini, pastikan Anda sudah memahami ringkasan sertifikat SSL dalam dokumentasi Cloud Load Balancing.
Metode konfigurasi Certificate Manager
Certificate Manager menawarkan dua metode konfigurasi sertifikat
untuk Application Load Balancer yang menggunakan proxy HTTPS target dan proxy Network Load Balancer
yang menggunakan proxy SSL target. Ini adalah dua dari tiga kemungkinan metode konfigurasi sertifikat untuk Cloud Load Balancing. Untuk mengetahui informasi selengkapnya tentang
Pengelola Sertifikat dan Cloud Load Balancing, lihat
Metode konfigurasi
sertifikat dalam dokumentasi
load balancing.
Proxy target load balancer mereferensikan peta sertifikat
Pengelola Sertifikat: proxy target load balancer mereferensikan satu
peta sertifikat. Peta sertifikat
mendukung ribuan entri secara default, dan dapat diskalakan hingga jutaan
entri. Metode ini digunakan oleh Load Balancer Aplikasi eksternal dan Load Balancer Jaringan proxy eksternal yang
didukung oleh Google Front End (GFE):
Load Balancer Aplikasi eksternal global
Load Balancer Aplikasi Klasik
Load Balancer Jaringan proxy eksternal global
Load Balancer Jaringan proxy klasik
Proxy target load balancer mereferensikan sertifikat Pengelola Sertifikat secara langsung: proxy target load balancer dapat mereferensikan hingga 100 sertifikat Pengelola Sertifikat. Metode ini digunakan oleh Load Balancer Aplikasi berikut yang didukung oleh software proxy Envoy open source terkelola:
Load Balancer Aplikasi eksternal regional
Load Balancer Aplikasi internal regional
Load Balancer Aplikasi internal lintas region
Pengelola Sertifikat juga mendukung produk berikut, yang
mereferensikan sertifikat Pengelola Sertifikat sebagai bagian dari
konfigurasinya:
Gateway Secure Web Proxy mereferensikan sertifikat
Certificate Manager: sebelum dapat mengonfigurasi gateway Secure Web Proxy, Anda
harus membuat satu atau beberapa sertifikat Certificate Manager untuk
digunakan gateway. Untuk informasi selengkapnya, lihat Men-deploy sertifikat SSL dan Men-deploy instance Secure Web Proxy.
Layanan cache tepi Media CDN mereferensikan
sertifikat Pengelola Sertifikat: layanan cache tepi Media CDN
mendukung hingga lima sertifikat Pengelola Sertifikat. Untuk informasi selengkapnya, lihat Sertifikat SSL (TLS) dan Mengonfigurasi sertifikat SSL (TLS).
Jenis sertifikat
Certificate Manager mendukung sertifikat yang dikelola Google dan dikelola sendiri. Semua Load Balancer Aplikasi yang menggunakan proxy HTTPS target dan semua Load Balancer Jaringan proxy yang mendukung proxy SSL target dapat menggunakan sertifikat Pengelola Sertifikat yang dikelola Google atau yang dikelola sendiri.
Sertifikat Certificate Manager yang dikelola Google:
sertifikat yang Google Cloud diperoleh dan dikelola untuk Anda. Bergantung pada load balancer dan metode konfigurasi Pengelola Sertifikatnya, sertifikat Pengelola Sertifikat yang dikelola Google dapat disediakan menggunakan otorisasi load balancer, otorisasi DNS, atau menggunakan Certificate Authority Service (CA Service).
Sertifikat Certificate Manager yang dikelola sendiri: sertifikat yang Anda peroleh, sediakan, dan perpanjang sendiri.
Dukungan produk
Tabel berikut merangkum dukungan untuk sertifikat Certificate Manager yang dikelola Google dan dikelola sendiri berdasarkan produk.
Produk
Sertifikat yang dikelola Google
Sertifikat yang dikelola sendiri
Otorisasi load balancer
Otorisasi DNS
Certificate Authority Service (Layanan CA)
Load Balancer Aplikasi eksternal global dan Load Balancer Jaringan proxy
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-09-01 UTC."],[[["\u003cp\u003eThis page details how to deploy certificates using Certificate Manager, which supports both Google-managed and self-managed certificates.\u003c/p\u003e\n"],["\u003cp\u003eGoogle-managed certificates can be configured with DNS authorization, load balancer authorization, or through the Certificate Authority Service (CA Service), and can be global or regional.\u003c/p\u003e\n"],["\u003cp\u003eDeployment methods vary based on the load balancer type, such as global external, classic, or cross-region internal, with different steps for Google-managed and self-managed certificates.\u003c/p\u003e\n"],["\u003cp\u003eTo deploy a certificate to a global external Application Load Balancer, classic Application Load Balancer, or a global external proxy Network Load Balancer you can either deploy a Google-managed certificate, or deploy a self-managed certificate.\u003c/p\u003e\n"],["\u003cp\u003eIf migrating an existing certificate to Certificate Manager is required, there is a dedicated guide available, and mutual TLS authentication (mTLS) is supported and documented in the Cloud Load Balancing documentation.\u003c/p\u003e\n"]]],[],null,["# Deployment overview\n\nThis page provides an overview of how to use Certificate Manager to\nprovision Google-managed and self-managed certificates for\nApplication Load Balancers and proxy Network Load Balancers.\n\nBefore reading this page, ensure that you're familiar with the [SSL certificates\noverview](/load-balancing/docs/ssl-certificates) in the Cloud Load Balancing\ndocumentation.\n\nCertificate Manager configuration methods\n-----------------------------------------\n\nCertificate Manager offers two certificate configuration methods\nfor Application Load Balancers using target HTTPS proxies and proxy Network Load Balancers\nusing target SSL proxies. These are two of three possible certificate\nconfiguration methods for Cloud Load Balancing. For more information about\nCertificate Manager and Cloud Load Balancing, see\n[Certificate configuration\nmethods](/load-balancing/docs/ssl-certificates#config-tech) in the load\nbalancing documentation.\n\n- **Load balancer's target proxy references a Certificate Manager\n certificate map** : the load balancer's target proxy references a single\n [certificate map](/certificate-manager/docs/maps). The certificate map\n supports thousands of entries by default, and can scale to millions of\n entries. This method is used by external Application Load Balancers and external proxy Network Load Balancers that\n are powered by Google Front Ends (GFEs):\n\n - Global external Application Load Balancers\n - Classic Application Load Balancers\n - Global external proxy Network Load Balancers\n - Classic proxy Network Load Balancers\n- **Load balancer's target proxy references Certificate Manager\n certificates directly** : the load balancer's target proxy can reference up to\n 100 [Certificate Manager\n certificates](/certificate-manager/docs/certificates). This method is used by\n the following Application Load Balancers that are powered by managed\n [open-source Envoy proxy](https://www.envoyproxy.io/) software:\n\n - Regional external Application Load Balancers\n - Regional internal Application Load Balancers\n - Cross-region internal Application Load Balancers\n\nCertificate Manager also supports the following products, which\nreference Certificate Manager certificates as part of their\nconfiguration:\n\n- **Secure Web Proxy gateway references Certificate Manager\n certificates** : before you can configure a Secure Web Proxy gateway, you\n create one or more Certificate Manager certificates for the\n gateway to use. For more information, see [Deploy an SSL\n certificate](/secure-web-proxy/docs/initial-setup-steps#create-upload-ssl-certificate)\n and [Deploy a Secure Web Proxy\n instance](/secure-web-proxy/docs/quickstart).\n\n- **Media CDN edge cache service references\n Certificate Manager certificates** : a Media CDN\n edge cache service supports up to five Certificate Manager\n certificates. For more information, see [SSL (TLS)\n Certificates](/media-cdn/docs/ssl-certificates) and [Configure SSL (TLS)\n certificates](/media-cdn/docs/configure-ssl-certificates).\n\nCertificate types\n-----------------\n\nCertificate Manager supports both Google-managed and\nself-managed certificates. All Application Load Balancers using target HTTPS\nproxies and all proxy Network Load Balancers that support target SSL proxies can use\neither Google-managed or self-managed Certificate Manager\ncertificates.\n\n- **Google-managed Certificate Manager certificates**:\n certificates that Google Cloud obtains and manages for you. Depending\n on the load balancer and its Certificate Manager configuration\n method, Google-managed Certificate Manager certificates can be\n provisioned by using load balancer authorization, DNS authorization, or by\n using Certificate Authority Service (CA Service).\n\n- **Self-managed Certificate Manager certificates**:\n certificates that you obtain, provision, and renew yourself.\n\nProduct support\n---------------\n\nThe following table summarizes the support for Google-managed and self-managed\nCertificate Manager certificates by product.\n\nWhat's next\n-----------\n\n- If you want to migrate an existing certificate from your load balancer to Certificate Manager, follow the instructions in [Migrate a\n certificate to Certificate Manager](/certificate-manager/docs/migrate).\n- For more information about Certificate Manager and GFE-based load balancers, see [How Certificate Manager\n works](/certificate-manager/docs/how-it-works).\n- If you want to use mutual TLS authentication (mTLS), see [Mutual TLS authentication](/load-balancing/docs/mtls) in the Cloud Load Balancing documentation."]]