Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Certificate Manager menyederhanakan akuisisi, deployment, dan pengelolaan sertifikat Transport Layer Security (TLS).
Pengelola Sertifikat mendukung deployment sertifikat global dan regional di load balancer Google Cloud , sertifikat regional di proxy
Secure Web Proxy, dan sertifikat global di Media CDN.
Load balancer yang didukung
Load balancerGoogle Cloud yang merujuk ke proxy HTTPS target atau proxy SSL target (TargetSslProxy) menggunakan sertifikat TLS untuk mengenkripsi informasi yang dikirim melalui jaringan.
Untuk menggunakan Pengelola Sertifikat, load balancer Anda harus kompatibel dengan Network Service Tier yang sesuai. Untuk mengetahui
perincian lengkap jenis load balancer dan dukungan tingkat layanan jaringannya masing-masing, lihat Ringkasan Google Cloud load
balancer.
Pengelola Sertifikat mendukung resource load balancer berikut:
Proxy HTTPS target yang digunakan oleh Load Balancer Aplikasi
Proxy SSL target yang digunakan oleh Load Balancer Jaringan proxy
Load Balancer Aplikasi eksternal global
Load Balancer Aplikasi Klasik
Load Balancer Aplikasi eksternal regional
Load Balancer Aplikasi internal regional
Load Balancer Aplikasi internal lintas region
Load Balancer Jaringan proxy eksternal global
Load Balancer Jaringan proxy klasik
Untuk informasi selengkapnya tentang perbedaan antara jenis proxy HTTPS target dan SSL target, lihat Proxy target.
Sertifikat TLS yang didukung
Pengelola Sertifikat mendukung jenis sertifikat TLS
berikut:
Sertifikat yang dikelola Google: sertifikat yang diperoleh dan dikelola Google Clouduntuk Anda. Dengan menggunakan Pengelola Sertifikat, Anda
dapat otomatis menerbitkan dan memperpanjang sertifikat yang dikelola Google. Jika ingin
menggunakan rantai kepercayaan Anda sendiri, bukan mengandalkan certificate authority (CA)
publik untuk menerbitkan sertifikat, Anda dapat mengonfigurasi
Pengelola Sertifikat untuk menggunakan kumpulan
CA dari
Certificate Authority Service sebagai penerbit sertifikat.
Sertifikat yang dikelola sendiri: sertifikat yang Anda peroleh, sediakan, dan
perpanjang sendiri. Anda mengupload sertifikat secara manual ke
Certificate Manager dan mengelolanya. Anda dapat menggunakan sertifikat
yang diterbitkan oleh CA pihak ketiga, atau CA yang Anda percayai, atau sertifikat
yang ditandatangani sendiri.
Untuk informasi selengkapnya tentang sertifikat yang didukung, lihat
Sertifikat.
Manfaat
Pengelola Sertifikat menawarkan manfaat berikut:
Otomatisasi
Otomatis menerbitkan, memperpanjang, dan mengelola sertifikat yang dikelola Google.
Sediakan sertifikat yang dikelola Google terlebih dahulu untuk memungkinkan migrasi yang lancar dan tanpa periode nonaktif ke Google Cloud.
Keamanan
Menyimpan dan men-deploy jutaan sertifikat dengan aman.
Amankan konfigurasi Anda dengan sertifikat yang dikelola Google, sehingga Anda tidak perlu mengelola kunci pribadi sertifikat.
Terapkan autentikasi TLS bersama (mTLS) di load balancer untuk keamanan yang lebih baik. Untuk mengetahui informasi selengkapnya, lihat Ringkasan TLS
timbal balik dalam dokumentasi Cloud Load Balancing.
Fleksibilitas
Verifikasi kepemilikan domain menggunakan metode otorisasi berbasis DNS atau load
balancer.
Pilih antara sertifikat yang dikelola Google (otomatis ditangani oleh
Google) atau sertifikat yang dikelola sendiri (diperoleh dan dikelola
secara independen).
Gunakan protokol ACME untuk mendapatkan sertifikat tepercaya secara publik untuk endpoint
yang Anda kelola dari Certificate Authority Publik. Untuk informasi selengkapnya, lihat
CA Publik.
Kelola semua sertifikat secara terpadu menggunakan konsol Google Cloud , Google Cloud CLI, atau Certificate Manager API.
Mengontrol penetapan dan pemilihan sertifikat berdasarkan nama domain. Hal ini memungkinkan Anda mengelola dan menayangkan lebih banyak sertifikat daripada dengan sertifikat SSL Compute Engine.
Kontrol penetapan dan pemilihan sertifikat berdasarkan nama host
pada tingkat terperinci.
Batasan
Pengelola Sertifikat memiliki batasan berikut:
Certificate Manager hanya mendukung Certificate Authority Publik dan
Let's Encrypt CA untuk menerbitkan sertifikat yang dikelola Google
dan tepercaya secara publik.
Certificate Manager hanya mendukung Certificate Authority Service untuk
menerbitkan sertifikat yang dikelola Google dan dipercaya secara pribadi.
Jumlah domain yang diizinkan di kolom Nama Alternatif Subjek (SAN) untuk sertifikat yang dikelola Google dibatasi hingga maksimum 100 saat menggunakan otorisasi DNS dan maksimum lima saat menggunakan otorisasi load balancer.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-19 UTC."],[[["\u003cp\u003eCertificate Manager facilitates the acquisition and management of TLS certificates for various load balancer resources, including Application Load Balancers and proxy Network Load Balancers, as well as regional Secure Web Proxy proxies.\u003c/p\u003e\n"],["\u003cp\u003eIt allows for the use of Google-managed certificates, which can be automatically issued and renewed, or self-managed certificates, including those issued by third-party CAs or self-signed certificates.\u003c/p\u003e\n"],["\u003cp\u003eCertificate Manager offers enhanced control over certificate assignment based on hostnames, supporting up to a million certificates per load balancer, significantly more than Cloud Load Balancing's limitations.\u003c/p\u003e\n"],["\u003cp\u003eCertificate Manager offers the ability to manage certificates in a centralized way using the Google Cloud CLI or the API, allowing for advanced control and management.\u003c/p\u003e\n"],["\u003cp\u003eGoogle-managed certificates can be requested directly through Certificate Manager, providing publicly trusted TLS certificates for encrypting internet traffic, and can use DNS authorization.\u003c/p\u003e\n"]]],[],null,["# Certificate Manager overview\n\nCertificate Manager simplifies the acquisition, deployment, and\nmanagement of Transport Layer Security (TLS) certificates.\nCertificate Manager supports deployment of global and regional\ncertificates on Google Cloud load balancers, regional certificates on [Secure Web Proxy](/secure-web-proxy/docs/overview) proxies, and global certificates\non [Media CDN](/media-cdn/docs/overview).\n\nSupported load balancers\n------------------------\n\nGoogle Cloud load balancers that refer to a target HTTPS proxy or a target\nSSL proxy (`TargetSslProxy`) use TLS certificates to encrypt information sent\nover the network.\n\nTo use Certificate Manager, your load balancer must be compatible\nwith the corresponding [Network Service Tier](/network-tiers/docs/overview). For\na comprehensive breakdown of load balancer types and their respective network\nservice tier support, see [Summary of Google Cloud load\nbalancers](/load-balancing/docs/choosing-load-balancer#summary-gclb).\n\nCertificate Manager supports the following load balancer\nresources:\n\nFor more information about the differences between target HTTPS and target SSL\nproxy types, see [Target proxies](/load-balancing/docs/target-proxies).\n\nSupported TLS certificates\n--------------------------\n\nCertificate Manager supports the following types of TLS\ncertificates:\n\n- **Google-managed certificates** : certificates that Google Cloud\n obtains and manages for you. Using Certificate Manager, you\n can automatically issue and renew Google-managed certificates. If you want\n to use your own trust chain rather than rely on public\n certificate authorities (CAs) to issue your certificates, you can configure\n Certificate Manager to [use a CA\n pool](/certificate-authority-service/docs/creating-ca-pool) from the\n Certificate Authority Service as the certificate issuer instead.\n\n- **Self-managed certificates** : certificates that you obtain, provision, and\n renew yourself. You manually upload the certificates to\n Certificate Manager and manage them. You can use certificates\n issued by third-party CAs, or CAs you trust, or your own [self-signed\n certificates](/load-balancing/docs/ssl-certificates/self-managed-certs#create-key-and-cert).\n\nFor more information about the supported certificates, see\n[Certificates](/certificate-manager/docs/how-it-works#certificates).\n\nBenefits\n--------\n\nCertificate Manager offers the following benefits:\n\n**Automation**\n\n- Automatically issue, renew, and manage Google-managed certificates.\n- Provision Google-managed certificates in advance to enable seamless, zero-downtime migrations to Google Cloud.\n\n**Security**\n\n- Securely store and deploy millions of certificates.\n- Secure your configurations with Google-managed certificates, eliminating the need to manage certificate private keys.\n- Implement mutual TLS (mTLS) authentication on your load balancer for enhanced security. For more information, see [Mutual TLS\n overview](/load-balancing/docs/mtls) in the Cloud Load Balancing documentation.\n\n**Flexibility**\n\n- Verify ownership of domains using either DNS-based or load balancer-based authorization methods.\n- Choose between Google-managed certificates (automatically handled by Google) or self-managed certificates (obtained and managed independently).\n- Use the ACME protocol to get publicly trusted certificates for endpoints you manage from the Public Certificate Authority. For more information, see [Public CA](/certificate-manager/docs/public-ca).\n- Manage all certificates in a unified manner using the Google Cloud console, Google Cloud CLI, or the Certificate Manager API.\n- Control certificate assignment and selection based on domain names. This lets you manage and serve larger numbers of certificates than with [Compute Engine SSL certificates](/load-balancing/docs/ssl-certificates#config-tech).\n- Control the assignment and selection of certificates based on hostnames at a granular level.\n\nLimitations\n-----------\n\nCertificate Manager has the following limitations:\n\n- Certificate Manager only supports the Public Certificate Authority and the Let's Encrypt CA for issuing publicly trusted Google-managed certificates.\n- Certificate Manager only supports Certificate Authority Service for issuing privately trusted Google-managed certificates.\n- The number of domains allowed in the Subject Alternative Names (SANs) field for Google-managed certificates is limited to a maximum of 100 when using DNS authorization and to a maximum of five when using load balancer authorization.\n- Google-managed certificates have limitations on the length of supported domain names. For more information, see [Domain name length limitations for\n Google-managed\n certificates](/certificate-manager/docs/quotas#domain_name_length_limitations_for_google-managed_certificates).\n- Certificates with the `ALL_REGIONS` scope don't support load balancer authorization.\n\nWhat's next\n-----------\n\n- [Core components of Certificate Manager](/certificate-manager/docs/core-components)\n- [How Certificate Manager works](/certificate-manager/docs/certificate-selection-logic)"]]