負載平衡器的目標 Proxy 參照 Certificate Manager 憑證對應關係:負載平衡器的目標 Proxy 參照單一憑證對應關係。憑證對應關係預設支援數千個項目,可擴充至數百萬個項目。外部應用程式負載平衡器和外部 Proxy 網路負載平衡器會使用這個方法,這些負載平衡器由 Google Front End (GFE) 提供支援:
Certificate Manager 支援 Google 代管和自行管理的憑證。所有使用目標 HTTPS Proxy 的應用程式負載平衡器,以及所有支援目標 SSL Proxy 的 Proxy 網路負載平衡器,都可以使用 Google 代管或自行管理的 Certificate Manager 憑證。
Google 代管的憑證管理工具憑證: Google Cloud 為您取得及管理的憑證。視負載平衡器及其 Certificate Manager 設定方法而定,您可以使用負載平衡器授權、DNS 授權,或使用憑證授權單位服務 (CA 服務) 來佈建 Google 代管的 Certificate Manager 憑證。
自行管理的憑證管理工具憑證:您自行取得、佈建及更新的憑證。
產品支援
下表列出各項產品支援的 Google 代管和自行管理 Certificate Manager 憑證。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-04 (世界標準時間)。"],[[["\u003cp\u003eThis page details how to deploy certificates using Certificate Manager, which supports both Google-managed and self-managed certificates.\u003c/p\u003e\n"],["\u003cp\u003eGoogle-managed certificates can be configured with DNS authorization, load balancer authorization, or through the Certificate Authority Service (CA Service), and can be global or regional.\u003c/p\u003e\n"],["\u003cp\u003eDeployment methods vary based on the load balancer type, such as global external, classic, or cross-region internal, with different steps for Google-managed and self-managed certificates.\u003c/p\u003e\n"],["\u003cp\u003eTo deploy a certificate to a global external Application Load Balancer, classic Application Load Balancer, or a global external proxy Network Load Balancer you can either deploy a Google-managed certificate, or deploy a self-managed certificate.\u003c/p\u003e\n"],["\u003cp\u003eIf migrating an existing certificate to Certificate Manager is required, there is a dedicated guide available, and mutual TLS authentication (mTLS) is supported and documented in the Cloud Load Balancing documentation.\u003c/p\u003e\n"]]],[],null,["# Deployment overview\n\nThis page provides an overview of how to use Certificate Manager to\nprovision Google-managed and self-managed certificates for\nApplication Load Balancers and proxy Network Load Balancers.\n\nBefore reading this page, ensure that you're familiar with the [SSL certificates\noverview](/load-balancing/docs/ssl-certificates) in the Cloud Load Balancing\ndocumentation.\n\nCertificate Manager configuration methods\n-----------------------------------------\n\nCertificate Manager offers two certificate configuration methods\nfor Application Load Balancers using target HTTPS proxies and proxy Network Load Balancers\nusing target SSL proxies. These are two of three possible certificate\nconfiguration methods for Cloud Load Balancing. For more information about\nCertificate Manager and Cloud Load Balancing, see\n[Certificate configuration\nmethods](/load-balancing/docs/ssl-certificates#config-tech) in the load\nbalancing documentation.\n\n- **Load balancer's target proxy references a Certificate Manager\n certificate map** : the load balancer's target proxy references a single\n [certificate map](/certificate-manager/docs/maps). The certificate map\n supports thousands of entries by default, and can scale to millions of\n entries. This method is used by external Application Load Balancers and external proxy Network Load Balancers that\n are powered by Google Front Ends (GFEs):\n\n - Global external Application Load Balancers\n - Classic Application Load Balancers\n - Global external proxy Network Load Balancers\n - Classic proxy Network Load Balancers\n- **Load balancer's target proxy references Certificate Manager\n certificates directly** : the load balancer's target proxy can reference up to\n 100 [Certificate Manager\n certificates](/certificate-manager/docs/certificates). This method is used by\n the following Application Load Balancers that are powered by managed\n [open-source Envoy proxy](https://www.envoyproxy.io/) software:\n\n - Regional external Application Load Balancers\n - Regional internal Application Load Balancers\n - Cross-region internal Application Load Balancers\n\nCertificate Manager also supports the following products, which\nreference Certificate Manager certificates as part of their\nconfiguration:\n\n- **Secure Web Proxy gateway references Certificate Manager\n certificates** : before you can configure a Secure Web Proxy gateway, you\n create one or more Certificate Manager certificates for the\n gateway to use. For more information, see [Deploy an SSL\n certificate](/secure-web-proxy/docs/initial-setup-steps#create-upload-ssl-certificate)\n and [Deploy a Secure Web Proxy\n instance](/secure-web-proxy/docs/quickstart).\n\n- **Media CDN edge cache service references\n Certificate Manager certificates** : a Media CDN\n edge cache service supports up to five Certificate Manager\n certificates. For more information, see [SSL (TLS)\n Certificates](/media-cdn/docs/ssl-certificates) and [Configure SSL (TLS)\n certificates](/media-cdn/docs/configure-ssl-certificates).\n\nCertificate types\n-----------------\n\nCertificate Manager supports both Google-managed and\nself-managed certificates. All Application Load Balancers using target HTTPS\nproxies and all proxy Network Load Balancers that support target SSL proxies can use\neither Google-managed or self-managed Certificate Manager\ncertificates.\n\n- **Google-managed Certificate Manager certificates**:\n certificates that Google Cloud obtains and manages for you. Depending\n on the load balancer and its Certificate Manager configuration\n method, Google-managed Certificate Manager certificates can be\n provisioned by using load balancer authorization, DNS authorization, or by\n using Certificate Authority Service (CA Service).\n\n- **Self-managed Certificate Manager certificates**:\n certificates that you obtain, provision, and renew yourself.\n\nProduct support\n---------------\n\nThe following table summarizes the support for Google-managed and self-managed\nCertificate Manager certificates by product.\n\nWhat's next\n-----------\n\n- If you want to migrate an existing certificate from your load balancer to Certificate Manager, follow the instructions in [Migrate a\n certificate to Certificate Manager](/certificate-manager/docs/migrate).\n- For more information about Certificate Manager and GFE-based load balancers, see [How Certificate Manager\n works](/certificate-manager/docs/how-it-works).\n- If you want to use mutual TLS authentication (mTLS), see [Mutual TLS authentication](/load-balancing/docs/mtls) in the Cloud Load Balancing documentation."]]