File: //snap/google-cloud-cli/current/help/man/man1/gcloud_privateca_roots_disable.1
.TH "GCLOUD_PRIVATECA_ROOTS_DISABLE" 1
.SH "NAME"
.HP
gcloud privateca roots disable \- disable a root certificate authority
.SH "SYNOPSIS"
.HP
\f5gcloud privateca roots disable\fR (\fICERTIFICATE_AUTHORITY\fR\ :\ \fB\-\-location\fR=\fILOCATION\fR\ \fB\-\-pool\fR=\fIPOOL\fR) [\fB\-\-ignore\-dependent\-resources\fR] [\fIGCLOUD_WIDE_FLAG\ ...\fR]
.SH "DESCRIPTION"
Disables a root certificate authority. The root certificate authority will not
be allowed to issue certificates once disabled. It may still revoke certificates
and/or generate CRLs. The CA certfificate will still be included in the
FetchCaCertificates response for the parent CA Pool.
.SH "EXAMPLES"
To disable a root CA:
.RS 2m
$ gcloud privateca roots disable prod\-root \-\-pool=prod\-root\-pool \e
\-\-location=us\-west1
.RE
.SH "POSITIONAL ARGUMENTS"
.RS 2m
.TP 2m
CERTIFICATE AUTHORITY resource \- The certificate authority to disable. The
arguments in this group can be used to specify the attributes of this resource.
(NOTE) Some attributes are not given arguments in this group but can be set in
other ways.
To set the \f5project\fR attribute:
.RS 2m
.IP "\(em" 2m
provide the argument \f5CERTIFICATE_AUTHORITY\fR on the command line with a
fully specified name;
.IP "\(em" 2m
provide the argument \f5\-\-project\fR on the command line;
.IP "\(em" 2m
set the property \f5core/project\fR.
.RE
.sp
This must be specified.
.RS 2m
.TP 2m
\fICERTIFICATE_AUTHORITY\fR
ID of the CERTIFICATE_AUTHORITY or fully qualified identifier for the
CERTIFICATE_AUTHORITY.
To set the \f5certificate_authority\fR attribute:
.RS 2m
.IP "\(bu" 2m
provide the argument \f5CERTIFICATE_AUTHORITY\fR on the command line.
.RE
.sp
This positional argument must be specified if any of the other arguments in this
group are specified.
.TP 2m
\fB\-\-location\fR=\fILOCATION\fR
The location of the CERTIFICATE_AUTHORITY.
To set the \f5location\fR attribute:
.RS 2m
.IP "\(bu" 2m
provide the argument \f5CERTIFICATE_AUTHORITY\fR on the command line with a
fully specified name;
.IP "\(bu" 2m
provide the argument \f5\-\-location\fR on the command line;
.IP "\(bu" 2m
set the property \f5privateca/location\fR.
.RE
.sp
.TP 2m
\fB\-\-pool\fR=\fIPOOL\fR
The parent CA Pool of the CERTIFICATE_AUTHORITY.
To set the \f5pool\fR attribute:
.RS 2m
.IP "\(bu" 2m
provide the argument \f5CERTIFICATE_AUTHORITY\fR on the command line with a
fully specified name;
.IP "\(bu" 2m
provide the argument \f5\-\-pool\fR on the command line.
.RE
.sp
.RE
.RE
.sp
.SH "FLAGS"
.RS 2m
.TP 2m
\fB\-\-ignore\-dependent\-resources\fR
This field skips the integrity check that would normally prevent breaking a CA
Pool if it is used by another cloud resource and allows the CA Pool to be in a
state where it is not able to issue certificates. Doing so may result in
unintended and unrecoverable effects on any dependent resource(s) since the CA
Pool would not be able to issue certificates.
.RE
.sp
.SH "GCLOUD WIDE FLAGS"
These flags are available to all commands: \-\-access\-token\-file, \-\-account,
\-\-billing\-project, \-\-configuration, \-\-flags\-file, \-\-flatten,
\-\-format, \-\-help, \-\-impersonate\-service\-account, \-\-log\-http,
\-\-project, \-\-quiet, \-\-trace\-token, \-\-user\-output\-enabled,
\-\-verbosity.
Run \fB$ gcloud help\fR for details.