联合工作负载的身份反射
bookmark_borderbookmark
使用集合让一切井井有条
根据您的偏好保存内容并对其进行分类。
您可以将证书授权机构服务与工作负载身份池和身份反射结合使用,联合第三方身份并获取用于证明此身份的证书。
身份反射是一种特殊的证书颁发模式,它限制了无特权证书请求者只能请求具有与其凭据中的身份对应的正文备用名称 (SAN) 的证书。例如,具有联合第三方身份令牌的 Cloud Service Mesh 工作负载或许能够请求包含与其 Mesh 身份对应的 SAN 的证书,但无法请求包含任何其他 SAN 的证书。
后续步骤
如未另行说明,那么本页面中的内容已根据知识共享署名 4.0 许可获得了许可,并且代码示例已根据 Apache 2.0 许可获得了许可。有关详情,请参阅 Google 开发者网站政策。Java 是 Oracle 和/或其关联公司的注册商标。
最后更新时间 (UTC):2025-03-06。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-03-06。"],[[["Identity reflection allows federating a third-party identity to obtain a certificate that attests to that identity through the Certificate Authority Service and workload identity pools."],["This process restricts certificate requesters to only request certificates with a subject alternative name (SAN) that matches their identity."],["Identity reflection is especially useful for workloads, like those in Cloud Service Mesh, that use federated third-party identity tokens."],["You can use Identity reflection with IAM workload identity federation to reflect third-party identities."]]],[]]