ListTLSCipherPolicies

Updated at:

Queries TLS policies.

Operation description

This feature is not enabled by default. We recommend that you use ALB or NLB. For special cases, contact sales or submit a ticket.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

slb:ListTLSCipherPolicies

list

*TLSPolicy

acs:slb:{#regionId}:{#AccountId}:tlspolicy/*

None None

Request parameters

Parameter

Type

Required

Description

Example

RegionId

string

Yes

The region ID of the Server Load Balancer instance.

Call the DescribeRegions API to query the region ID.

cn-hangzhou

TLSCipherPolicyId

string

No

The ID of the TLS policy.

tls-bp17elso1h323r****

Name

string

No

The name of the TLS policy. The name must be 2 to 200 characters in length. It must start with a letter or a Chinese character. It can contain digits, periods (.), underscores (_), and hyphens (-).

TLSPolicy-test****

IncludeListener

boolean

No

Specify whether to return the associated listener information. Valid values:

  • true: Return the information.

  • false (default): Do not return the information.

false

NextToken

string

No

Specify whether a token is available for the next query. Valid values:

  • Do not specify this parameter for the first query or if no next query exists.

  • If a next query exists, set this parameter to the NextToken value returned from the previous API call.

FFmyTO70tTpLG6I3FmYAXGKPd****

MaxItems

integer

No

The maximum number of TLS policies to read in this query. Valid values: 1 to 100. If you leave this parameter empty, the default value is 20.

20

Response elements

Element

Type

Description

Example

object

NextToken

string

Indicates whether a token is available for the next query. Valid values:

  • If NextToken is empty, no next query exists.

  • If NextToken returns a value, this value indicates the token for the start of the next query.

FFmyTO70tTpLG6I3FmYAXGKPd****

RequestId

string

The request ID.

CEF72CEB-54B6-4AE8-B225-F876FF7BA984

TotalCount

integer

The total number of TLS policies that meet the request conditions.

1000

IsTruncated

boolean

Indicates whether the query is complete. Valid values:

  • true: The current page is the last page.

  • false: A next page exists.

false

TLSCipherPolicies

array<object>

The list of TLS policies.

array<object>

Status

string

The instance status of the TLS policy. Valid values:

  • configuring: The policy is being configured.

  • normal: The policy is normal.

normal

InstanceId

string

The instance ID of the TLS policy.

tls-bp17elso1h323r****

Name

string

The name of the TLS policy.

TLSPolicy-test****

CreateTime

integer

The UNIX timestamp when the policy was created.

1608273800000

RelateListeners

array<object>

The associated listeners.

object

Port

integer

The listening port. Valid values: 1 to 65535.

80

Protocol

string

The listening protocol. Valid values:

  • TCP

  • UDP

  • HTTP

  • HTTPS

HTTPS

LoadBalancerId

string

The ID of the Server Load Balancer instance.

lb-bp1b6c719dfa08ex****

TLSVersions

array

string

The supported TLS protocol versions.

TLSv1.0

Ciphers

array

string

The supported cipher suites. This depends on the value of TLSVersions.

TLSv1.0 and TLSv1.1 support:

  • ECDHE-ECDSA-AES128-SHA

  • ECDHE-ECDSA-AES256-SHA

  • ECDHE-RSA-AES128-SHA

  • ECDHE-RSA-AES256-SHA

  • AES128-SHA AES256-SHA

  • DES-CBC3-SHA

TLSv1.2 supports:

  • ECDHE-ECDSA-AES128-SHA

  • ECDHE-ECDSA-AES256-SHA

  • ECDHE-RSA-AES128-SHA

  • ECDHE-RSA-AES256-SHA

  • AES128-SHA AES256-SHA

  • DES-CBC3-SHA

  • ECDHE-ECDSA-AES128-GCM-SHA256

  • ECDHE-ECDSA-AES256-GCM-SHA384

  • ECDHE-ECDSA-AES128-SHA256

  • ECDHE-ECDSA-AES256-SHA384

  • ECDHE-RSA-AES128-GCM-SHA256

  • ECDHE-RSA-AES256-GCM-SHA384

  • ECDHE-RSA-AES128-SHA256

  • ECDHE-RSA-AES256-SHA384

  • AES128-GCM-SHA256

  • AES256-GCM-SHA384

  • AES128-SHA256 AES256-SHA256

TLSv1.3 supports:

  • TLS_AES_128_GCM_SHA256

  • TLS_AES_256_GCM_SHA384

  • TLS_CHACHA20_POLY1305_SHA256

  • TLS_AES_128_CCM_SHA256

  • TLS_AES_128_CCM_8_SHA256

ECDHE-ECDSA-AES128-SHA

Examples

Success response

JSON format

{
  "NextToken": "FFmyTO70tTpLG6I3FmYAXGKPd****",
  "RequestId": "CEF72CEB-54B6-4AE8-B225-F876FF7BA984",
  "TotalCount": 1000,
  "IsTruncated": false,
  "TLSCipherPolicies": [
    {
      "Status": "normal",
      "InstanceId": "tls-bp17elso1h323r****",
      "Name": "TLSPolicy-test****",
      "CreateTime": 1608273800000,
      "RelateListeners": [
        {
          "Port": 80,
          "Protocol": "HTTPS",
          "LoadBalancerId": "lb-bp1b6c719dfa08ex****"
        }
      ],
      "TLSVersions": [
        "TLSv1.0"
      ],
      "Ciphers": [
        "ECDHE-ECDSA-AES128-SHA"
      ]
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 QueryTokenInvalid The specified token is invalid.
400 QueryTokenNotExist The specified token is not exist.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.