Stay organized with collectionsSave and categorize content based on your preferences.
Enable, disable, and restore certificate authorities
This document explains how you can manage the state of your certificate authority
(CA).
Enable a CA
All subordinate CAs are created in theAWAITING_USER_ACTIVATIONstate, and
they are set to theSTAGEDstate after activation. All root CAs are created in
theSTAGEDstate by default. You must change the CA state toENABLEDto
include it in a CA pool's certificate issuance rotation. For more information
about the operational states of a CA, seeCertificate authority
states.
To enable a CA that is in theSTAGEDorDISABLEDstate, use the following
instructions:
Disabling a CA prevents it from issuing certificates. All certificate requests
to a disabled CA are rejected. Other functionalities, such as revoking
certificates, publishing Certificate Revocation Lists (CRLs), and updating the
CA metadata can still take place.
When a CA is scheduled for deletion, there is a 30-day grace period before it is
deleted. During the grace period, a CA Service Operation Manager
(roles/privateca.caManager) or CA Service
Admin (roles/privateca.admin) can stop the deletion process. You can restore a
CA only during the grace period.
To restore a CA that is scheduled to be deleted to the disabled state, use the
following instructions:
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-05-29 UTC."],[],[]]