Skip to main content

Read certificate status

The inventory summary counts certificates expiring within 30 days. Open a certificate to inspect its validity dates, domains, fingerprint, public certificate when available, and consuming distributions.

Managed issuance

Managed certificates can include issuance status, attempts, last error, start and finish times, and the next retry or retry-after time. Configure hostnames and managed TLS on the linked Cloud CDN distribution. Confirm that DNS points to its expected target and that the hostname is configured correctly before waiting for another attempt. Managed renewal is automatic. Imported certificates require you to supply replacement material before expiry.

Safe removal

The API rejects deletion of a managed certificate and rejects deletion of an imported certificate still used by a distribution. Detach or replace it on every consuming distribution, then delete the unused imported certificate from the inventory.

Troubleshooting

  • Upload rejected: check PEM encoding, matching key, chain order, validity, name, and project quota. If root CA validation is enabled, supply a complete chain to a trusted root.
  • Certificate not selectable: verify that the distribution and certificate belong to the same project and that your permissions allow certificate listing.
  • HTTPS hostname mismatch: compare the requested hostname with the certificate’s covered domains and the distribution’s configured hostnames.
  • Pending issuance: inspect the issuance error and retry information, validate DNS, and avoid repeated configuration changes while provisioning is underway.
For escalation, include the project, certificate and distribution IDs, hostname, and UTC failure time. Do not send private keys.