
本页面介绍了如何在单个区域中列出证书授权机构 (CA) Google Cloud 项目。

列出根 CA

本部分介绍如何查看根 CA。

跨 CA 池列出根 CA

如需列出各 CA 池中的所有根 CA,请执行以下操作:


  1. 在 Google Cloud 控制台中,前往 Certificate Authority Service 页面。

    转到 Certificate Authority Service

  2. 点击 CA 管理器标签页,以转到证书授权机构 页面。

  3. Filter 字段中,从列表中选择 Type

  4. 类型的值设置为

系统会列出类型设为的所有 CA。



gcloud privateca roots list --location LOCATION

LOCATION 替换为根 CA 的位置。如需查看位置的完整列表,请参阅位置

列出特定 CA 池中的根 CA

如需列出特定 CA 池中的所有根 CA,请按照以下说明操作:


  1. 转到 Certificate Authority Service 页面。

  2. 点击 CA 管理器标签页,以转到证书授权机构 页面。

  3. Filter 字段中,从列表中选择 Type

  4. 类型的值设置为

  5. 过滤条件字段中,从列表中选择

  6. 点击列表中的 CA 池的名称。



gcloud privateca roots list --location LOCATION --pool POOL_ID


  • LOCATION:CA 池的位置。如需查看位置的完整列表,请参阅位置
  • POOL_ID:CA 池的名称。

如需列出所有 CA 池和位置中的根 CA,请从命令中省略 --pool--location 标志。

如需详细了解 gcloud privateca roots list 命令,请参阅 gcloud privateca roots list

列出从属 CA

本部分介绍了如何查看子 CA。

跨 CA 池列出从属 CA

如需列出 CA 池中的所有从属 CA,请执行以下操作:


  1. 前往 Certificate Authority Service 页面。

  2. 点击 CA 管理器标签页,以转到证书授权机构页面。

  3. Filter 字段中, 从列表中选择类型

  4. 类型的值设置为从属

系统会列出所有将“Type”(类型)设置为“Subordinate”(从属)的 CA。



gcloud privateca subordinates list --location LOCATION

LOCATION 替换为从属 CA 的位置。如需查看完整的位置列表,请参阅 地理位置

列出特定 CA 池中的从属 CA

如需列出特定 CA 池中的所有从属 CA,请执行以下操作:


  1. 转到 Certificate Authority Service 页面。

  2. 点击 CA 管理器标签页,以转到证书授权机构页面。

  3. Filter 字段中, 从列表中选择类型

  4. 类型的值设置为下属

  5. 过滤条件字段中,从列表中选择

  6. 点击列表中的 CA 池名称。



gcloud privateca subordinates list --location LOCATION --pool POOL_ID


  • LOCATION:CA 池的位置。如需查看位置的完整列表,请参阅位置
  • POOL_ID:CA 池的名称。

如需详细了解 gcloud privateca subordinates list 命令,请参阅 gcloud privateca subordinates list

列出所有 CA

如需列出 CA 池中的所有 CA,请按照以下说明操作:


  1. 前往 Certificate Authority Service 页面。

  2. 点击 CA 管理器标签页,前往证书授权机构页面。

  3. Filter 字段中,从列表中选择 Pool

  4. 点击列表中的 CA 池名称。

或者,您也可以在 CA 池管理器页面上执行以下操作,查看特定 CA 池中的 CA:

  1. 点击 CA 池管理器标签页。
  2. CA 池页面上,点击要创建其 CA 的 CA 池的名称 想要观看的内容

CA 池详情页面上,您可以看到“池中的证书授权机构”下列出的 CA。您可以根据类型、层级、位置、状态等条件过滤 CA。


如需向 CA Service 进行身份验证,请设置应用默认凭据。 如需了解详情,请参阅为本地开发环境设置身份验证

import (

	privateca "cloud.google.com/go/security/privateca/apiv1"

// List all Certificate Authorities present in the given CA Pool.
func listCas(w io.Writer, projectId string, location string, caPoolId string) error {
	// projectId := "your_project_id"
	// location := "us-central1"	// For a list of locations, see: https://cloud.google.com/certificate-authority-service/docs/locations.
	// caPoolId := "ca-pool-id"		// The id of the CA pool under which the CAs to be listed are present.

	ctx := context.Background()
	caClient, err := privateca.NewCertificateAuthorityClient(ctx)
	if err != nil {
		return fmt.Errorf("NewCertificateAuthorityClient creation failed: %w", err)
	defer caClient.Close()

	fullCaPoolName := fmt.Sprintf("projects/%s/locations/%s/caPools/%s", projectId, location, caPoolId)

	// Create the ListCertificateAuthorities.
	// See https://pkg.go.dev/cloud.google.com/go/security/privateca/apiv1/privatecapb#ListCertificateAuthoritiesRequest.
	req := &privatecapb.ListCertificateAuthoritiesRequest{Parent: fullCaPoolName}

	it := caClient.ListCertificateAuthorities(ctx, req)
	for {
		resp, err := it.Next()
		if err == iterator.Done {
		if err != nil {
			return fmt.Errorf("unable to get the list of cerficate authorities: %w", err)

		fmt.Fprintf(w, " - %s (state: %s)", resp.Name, resp.State.String())

	return nil


import com.google.cloud.security.privateca.v1.CaPoolName;
import com.google.cloud.security.privateca.v1.CertificateAuthority;
import com.google.cloud.security.privateca.v1.CertificateAuthorityServiceClient;
import java.io.IOException;

public class ListCertificateAuthorities {

  public static void main(String[] args) throws IOException {
    // TODO(developer): Replace these variables before running the sample.
    // location: For a list of locations, see:
    // https://cloud.google.com/certificate-authority-service/docs/locations
    // poolId: The id of the CA pool under which the CAs to be listed are present.
    String project = "your-project-id";
    String location = "ca-location";
    String poolId = "ca-pool-id";
    listCertificateAuthority(project, location, poolId);

  // List all Certificate authorities present in the given CA Pool.
  public static void listCertificateAuthority(String project, String location, String poolId)
      throws IOException {
    // Initialize client that will be used to send requests. This client only needs to be created
    // once, and can be reused for multiple requests. After completing all of your requests, call
    // the `certificateAuthorityServiceClient.close()` method on the client to safely
    // clean up any remaining background resources.
    try (CertificateAuthorityServiceClient certificateAuthorityServiceClient =
        CertificateAuthorityServiceClient.create()) {

      // Create CA pool name comprising of project, location and the pool name.
      CaPoolName parent =

      // List the CA name and its corresponding state.
      for (CertificateAuthority certificateAuthority :
          certificateAuthorityServiceClient.listCertificateAuthorities(parent).iterateAll()) {
            certificateAuthority.getName() + " is " + certificateAuthority.getState());


import google.cloud.security.privateca_v1 as privateca_v1

def list_certificate_authorities(
    project_id: str, location: str, ca_pool_name: str
) -> None:
    List all Certificate authorities present in the given CA Pool.

        project_id: project ID or project number of the Cloud project you want to use.
        location: location you want to use. For a list of locations, see: https://cloud.google.com/certificate-authority-service/docs/locations.
        ca_pool_name: the name of the CA pool under which the CAs to be listed are present.

    caServiceClient = privateca_v1.CertificateAuthorityServiceClient()

    ca_pool_path = caServiceClient.ca_pool_path(project_id, location, ca_pool_name)

    # List the CA name and its corresponding state.
    for ca in caServiceClient.list_certificate_authorities(parent=ca_pool_path):
        print(ca.name, "is", ca.state)
