Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Google Distributed Cloud (GDC) dengan air gap menyediakan API infrastruktur kunci publik (PKI)
untuk mendapatkan sertifikat web. Halaman ini memberikan petunjuk untuk mengubah penerbit sertifikat default ke penerbit lain. Untuk mengetahui informasi selengkapnya tentang mode sertifikat PKI, lihat Konfigurasi sertifikat TLS web.
Sebelum memulai
Untuk mendapatkan izin yang diperlukan guna mengonfigurasi penerbit sertifikat default PKI, minta Admin IAM Organisasi Anda untuk memberi Anda peran Admin PKI Infra (infra-pki-admin) di namespace sistem.
Mengubah penerbit sertifikat default
Label penerbit default terlihat seperti contoh berikut. Untuk setiap namespace,
satu CertificateIssuer harus berisi label:
pki.security.gdc.goog/is-default-issuer:'true'
Melihat penerbit default saat ini di namespace pki-system:
Ganti NEW_DEFAULT_ISSUER dengan nama penerbit sertifikat default
baru.
Memicu penerbitan ulang sertifikat secara manual
Setelah Anda mengganti penerbit sertifikat default, Distributed Cloud tidak akan otomatis menerbitkan ulang sertifikat yang ditandatangani oleh penerbit sertifikat default sebelumnya, kecuali jika masa berlaku sertifikat akan segera berakhir. Untuk segera menerbitkan ulang sertifikat dengan penerbit default baru, lihat Menerbitkan ulang sertifikat web PKI secara manual.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-09-04 UTC."],[[["\u003cp\u003eGoogle Distributed Cloud (GDC) air-gapped uses a Public Key Infrastructure (PKI) API to manage web certificates, and you can change the default certificate issuer.\u003c/p\u003e\n"],["\u003cp\u003eTo change the default certificate issuer, you must have the \u003ccode\u003einfra-pki-admin\u003c/code\u003e role in the system namespace, and then modify the label of the current issuer to \u003ccode\u003efalse\u003c/code\u003e before labeling the new one to \u003ccode\u003etrue\u003c/code\u003e.\u003c/p\u003e\n"],["\u003cp\u003eThe default issuer is identified by the label \u003ccode\u003epki.security.gdc.goog/is-default-issuer: 'true'\u003c/code\u003e, and only one \u003ccode\u003eCertificateIssuer\u003c/code\u003e per namespace can have this label.\u003c/p\u003e\n"],["\u003cp\u003eAfter changing the default certificate issuer, certificates signed by the old issuer are not automatically reissued, unless they are near expiration, and instead a manual reissuance is needed.\u003c/p\u003e\n"]]],[],null,["# Change the default certificate issuer\n\nGoogle Distributed Cloud (GDC) air-gapped provides a [public key infrastructure (PKI) API](/distributed-cloud/hosted/docs/latest/gdch/apis/service/security/pki/v1/security-pki-v1)\nto get web certificates. This page provides instructions to change the\ndefault certificate issuer to another issuer. For more information about PKI\ncertificate modes, see [Web TLS certificate configuration](/distributed-cloud/hosted/docs/latest/gdch/platform/pa-user/pki/web-tls-cert-config).\n\nBefore you begin\n----------------\n\nTo get the permissions you need to configure the PKI default certificate issuer,\nask your Organization IAM Admin to grant you the Infra PKI Admin\n(`infra-pki-admin`) role in the system namespace.\n\nChange default certificate issuer\n---------------------------------\n\n1. The default issuer label looks like the following example. For each namespace,\n one `CertificateIssuer` must contain the label:\n\n pki.security.gdc.goog/is-default-issuer: 'true'\n\n2. View the current default issuer in the `pki-system` namespace:\n\n kubectl get certificateissuers -n pki-system -l pki.security.gdc.goog/is-default-issuer=true\n\n The output looks similar to the following: \n\n NAME READY REASON ISDEFAULT\n default-tls-ca-issuer True CAaaSReady true\n\n3. Edit the existing default issuer, and update the default issuer label\n from the issuer:\n\n kubectl label --overwrite certificateissuers \u003cvar translate=\"no\"\u003eCURRENT_DEFAULT_ISSUER\u003c/var\u003e -n pki-system pki.security.gdc.goog/is-default-issuer='false'\n\n Replace \u003cvar translate=\"no\"\u003eCURRENT_DEFAULT_ISSUER\u003c/var\u003e with the name of the\n current default certificate issuer.\n4. To set the new `CertificateIssuer` as the default issuer, update the label:\n\n kubectl label --overwrite certificateissuers \u003cvar translate=\"no\"\u003eNEW_DEFAULT_ISSUER\u003c/var\u003e -n pki-system pki.security.gdc.goog/is-default-issuer=true\n\n Replace \u003cvar translate=\"no\"\u003eNEW_DEFAULT_ISSUER\u003c/var\u003e with the name of the new\n default certificate issuer.\n\nManually trigger certificate reissuance\n---------------------------------------\n\nAfter you switch the default certificate issuer, Distributed Cloud\nwon't automatically reissue certificates signed by the previous default\ncertificate issuer unless the certificate is about to expire. To immediately\nreissue certificates with the new default issuer, see\n[Manually reissue PKI web certificates](/distributed-cloud/hosted/docs/latest/gdch/platform/pa-user/pki/pki-cert-reissue)."]]