使用Certbot(通配符)配置Google Cloud DNS时遇权限问题
Certbot签发通配符证书Google DNS权限403问题排查
报错信息
Encountered 403 Forbidden with reason "insufficientPermissions" Encountered 403 Forbidden with reason "insufficientPermissions" Error finding zone. Skipping cleanup. Encountered error finding managed zone: <HttpError 403 when requesting https://dns.googleapis.com/dns/v1/projects/example/managedZones?dnsName=example.com.&alt=json returned "Request had insufficient authentication scopes.". Details: "[{'message': 'Insufficient Permission', 'domain': 'global', 'reason': 'insufficientPermissions'}]">
已执行操作
- 为账号主邮箱在DNS Zone权限中添加DNS Admin角色
- 在项目IAM权限中为该邮箱添加DNS Reader角色
问题根源与解决步骤
核心问题
报错里的"Request had insufficient authentication scopes"是关键——这不是IAM角色权限不足,而是Certbot实际使用的认证凭据(大概率是服务账号密钥)的OAuth2权限范围不够,或者你误用了主邮箱身份而非服务账号。
Certbot的Google DNS插件默认需要通过服务账号密钥进行认证,而非主邮箱的交互式登录,你给主邮箱加的权限根本没被Certbot用到。
解决步骤
- 创建专用服务账号
- 登录Google Cloud控制台,进入对应项目,创建一个专门用于Certbot的服务账号。
- 分配项目级DNS Admin角色
- 给这个服务账号添加项目级别的DNS Admin角色(不要仅在单个DNS Zone设置权限),这样它才能查询项目下所有托管Zone,完成DNS01校验的域名解析操作。
- 下载服务账号密钥
- 为该服务账号生成并下载JSON格式的密钥文件,保存到服务器上Certbot可访问的路径。
- 指定密钥文件运行Certbot
- 执行Certbot命令时,添加
--dns-google-credentials /path/to/your-service-account-key.json参数,确保Certbot使用这个服务账号的身份认证。
- 执行Certbot命令时,添加
- 验证权限有效性
- 用gcloud命令测试服务账号权限:
gcloud dns managed-zones list --project example --account=your-service-account@example.iam.gserviceaccount.com - 如果能正常列出托管Zone,说明权限配置正确,再重新运行Certbot命令即可。
- 用gcloud命令测试服务账号权限:
内容的提问来源于stack exchange,提问作者Maciek
相关产品推荐
相关产品推荐

