You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Certbot(通配符)配置Google Cloud DNS时遇权限问题

Certbot签发通配符证书Google DNS权限403问题排查

报错信息

Encountered 403 Forbidden with reason "insufficientPermissions"
Encountered 403 Forbidden with reason "insufficientPermissions"
Error finding zone. Skipping cleanup.
Encountered error finding managed zone: <HttpError 403 when requesting https://dns.googleapis.com/dns/v1/projects/example/managedZones?dnsName=example.com.&alt=json returned "Request had insufficient authentication scopes.". Details: "[{'message': 'Insufficient Permission', 'domain': 'global', 'reason': 'insufficientPermissions'}]">

已执行操作

  • 为账号主邮箱在DNS Zone权限中添加DNS Admin角色
  • 在项目IAM权限中为该邮箱添加DNS Reader角色

问题根源与解决步骤

核心问题

报错里的"Request had insufficient authentication scopes"是关键——这不是IAM角色权限不足,而是Certbot实际使用的认证凭据(大概率是服务账号密钥)的OAuth2权限范围不够,或者你误用了主邮箱身份而非服务账号。

Certbot的Google DNS插件默认需要通过服务账号密钥进行认证,而非主邮箱的交互式登录,你给主邮箱加的权限根本没被Certbot用到。

解决步骤

  1. 创建专用服务账号
    • 登录Google Cloud控制台,进入对应项目,创建一个专门用于Certbot的服务账号。
  2. 分配项目级DNS Admin角色
    • 给这个服务账号添加项目级别的DNS Admin角色(不要仅在单个DNS Zone设置权限),这样它才能查询项目下所有托管Zone,完成DNS01校验的域名解析操作。
  3. 下载服务账号密钥
    • 为该服务账号生成并下载JSON格式的密钥文件,保存到服务器上Certbot可访问的路径。
  4. 指定密钥文件运行Certbot
    • 执行Certbot命令时,添加--dns-google-credentials /path/to/your-service-account-key.json参数,确保Certbot使用这个服务账号的身份认证。
  5. 验证权限有效性
    • 用gcloud命令测试服务账号权限:
      gcloud dns managed-zones list --project example --account=your-service-account@example.iam.gserviceaccount.com
      
    • 如果能正常列出托管Zone,说明权限配置正确,再重新运行Certbot命令即可。

内容的提问来源于stack exchange,提问作者Maciek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 21:27:25