Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Menyiapkan akses berbasis sertifikat
Untuk menyiapkan akses berbasis sertifikat (CBA), Anda harus membuat tingkat akses CBA baru, menerapkan tingkat akses CBA, dan mengaktifkan CBA di aplikasi klien.
Sebelum memulai
Pastikan ekstensi Chrome Verifikasi Endpoint dan aplikasi pendukung Verifikasi Endpoint di-deploy di semua perangkat yang memerlukan akses ke resource Google Cloud .
Perangkat ini menjadi perangkat tepercaya yang dapat Anda beri akses.
Terapkan tingkat akses CBA pada resource menggunakan salah satu metode berikut:
Batasi akses ke layanan Google Cloud
yang didukung Kontrol Layanan VPC dengan membuat perimeter Kontrol Layanan VPC dengan tingkat akses
CBA, lalu tambahkan layanan ke dalam perimeter. Untuk petunjuk
mendetail, lihat Mengaktifkan akses berbasis sertifikat dengan Kontrol Layanan
VPC.
Batasi akses ke semua layanan Google Cloud , termasuk konsol
Google Cloud , dengan mengikat tingkat akses CBA ke grup pengguna yang aksesnya ingin Anda batasi. Untuk mengetahui petunjuk mendetail, lihat Mengaktifkan akses berbasis sertifikat dengan grup pengguna.
Setelah Anda menerapkan CBA, akses ke resource tanpa sertifikat klien akan
ditolak. Untuk memberikan akses ke perangkat tepercaya, Anda harus memastikan bahwa klien Anda
mengirim sertifikat ke Google API dengan benar melalui koneksi
mTLS. Anda dapat melakukannya dengan mengaktifkan fitur CBA di klien
yang kompatibel dengan CBA menggunakan prosedur di Mengaktifkan akses
berbasis sertifikat di aplikasi klien.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-09-01 UTC."],[],[],null,["Set up certificate-based access To set up certificate-based access (CBA), you must create a new CBA access level, enforce the CBA access level, and enable CBA in your client applications.\n\nBefore you begin\n\nEnsure that the Endpoint Verification Chrome extension and the Endpoint Verification helper app are\ndeployed on all of the devices that require access to Google Cloud resources.\nThese become trusted devices to which you can grant access.\n\nIf you need to deploy Endpoint Verification, see [Deploying Endpoint Verification to use with certificate-based access](/chrome-enterprise-premium/docs/deploy-cba-endpoint-verification).\n\nSet up CBA\n\nTo set up CBA, complete the following steps:\n\n1. [Create a new CBA access level](/chrome-enterprise-premium/docs/create-cba-access-levels) that requires certificates when determining access to resources.\n\n2. Enforce the CBA access level on a resource using one of the following methods:\n\n - Restrict access to VPC Service Controls-supported Google Cloud services by creating a VPC Service Controls perimeter with the CBA access level, and then adding services into the perimeter. For detailed instructions, see [Enable certificate-based access with VPC Service\n Controls](/chrome-enterprise-premium/docs/enable-cba-vpcsc).\n - Restrict access to all Google Cloud services, including the Google Cloud console, by binding the CBA access level to a user group that you want to restrict access to. For detailed instructions, see [Enable certificate-based access with user groups](/chrome-enterprise-premium/docs/enable-cba-user-groups).\n3. After you enforce CBA, access to resources without client certificates is\n denied. To grant access to trusted devices, you must ensure that your clients\n are correctly sending certificates to the Google APIs through an mTLS\n connection. You can do that by enabling the CBA feature in your CBA\n compatible client using the procedure in [Enable certificate-based\n access in client applications](/chrome-enterprise-premium/docs/enable-cba-client-apps).\n\nWhat's next\n\n- Learn about [Securing resources with certificate-based access](/chrome-enterprise-premium/docs/securing-resources-with-certificate-based-access)"]]