SetTLSCipherPolicyAttribute
Configure a TLS cipher policy.
Operation description
This feature is not enabled by default. We recommend that you use Application Load Balancer (ALB) or Network Load Balancer (NLB). For special cases, contact your sales representative or submit a ticket.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
slb:SetTLSCipherPolicyAttribute |
update |
*TLSPolicy
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| RegionId |
string |
Yes |
The ID of the region where the Server Load Balancer (SLB) instance is deployed. You can call the DescribeRegions operation to query region IDs. |
cn-hangzhou |
| TLSCipherPolicyId |
string |
Yes |
The ID of the TLS cipher policy. |
tls-bp1lp2076qx4e******bridp |
| Name |
string |
Yes |
The name of the TLS cipher policy. The name must be 2 to 200 characters in length. It must start with a letter or a Chinese character. It can contain letters, digits, periods (.), underscores (_), and hyphens (-). |
tls-policy*****-test |
| TLSVersions |
array |
Yes |
The TLS protocol versions that the policy supports. Valid values: TLSv1.0, TLSv1.1, TLSv1.2, and TLSv1.3. |
TLSv1.0 |
|
string |
No |
The TLS protocol versions that the policy supports. Valid values: TLSv1.0, TLSv1.1, TLSv1.2, and TLSv1.3. |
TLSv1.0 |
|
| Ciphers |
array |
Yes |
The cipher suites that the policy supports. The supported cipher suites depend on the TLS protocol versions specified in TLSVersions. A cipher suite only needs to be supported by at least one of the TLS protocol versions in TLSVersions. For example, if TLSv1.3 is specified, the cipher suite list must include at least one cipher suite supported by TLSv1.3. Supported cipher suites for TLSv1.0 and TLSv1.1:
Supported cipher suites for TLSv1.2:
Supported cipher suites for TLSv1.3:
|
DES-CBC3-SHA |
|
string |
No |
The cipher suites that the policy supports. The supported cipher suites depend on the TLS protocol versions specified in TLSVersions. A cipher suite only needs to be supported by at least one of the TLS protocol versions in TLSVersions. For example, if TLSv1.3 is specified, the cipher suite list must include at least one cipher suite supported by TLSv1.3. Supported cipher suites for TLSv1.0 and TLSv1.1:
Supported cipher suites for TLSv1.2:
Supported cipher suites for TLSv1.3:
|
ECDHE-ECDSA-AES128-SHA |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| TaskId |
string |
The ID of the asynchronous task. |
72dcd26b-f12d-4c27-b3af****-18f6aed5 |
| RequestId |
string |
The ID of the request. |
CEF72CEB-54B6-4AE8-B225-F876******* |
Examples
Success response
JSON format
{
"TaskId": "72dcd26b-f12d-4c27-b3af****-18f6aed5",
"RequestId": "CEF72CEB-54B6-4AE8-B225-F876*******"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | MissingParam.Name | The param Name is missing. | |
| 400 | MissingParam.TlsVersions | The param TlsVersions is missing. | |
| 400 | MissingParam.Ciphers | The param Ciphers is missing. | |
| 400 | ParamDuplicateError.TlsVersions | The param TlsVersions is duplicate in request. | |
| 400 | ParamDuplicateError.Ciphers | The param Ciphers is duplicate in request. | |
| 400 | TLSPolicyNoSupportVersion | The specified TLS version is not supported. | |
| 400 | TLSPolicyNoSupportCipher | The specified TLS cipher is not supported. | |
| 400 | MissingParam.TLSCipherPolicyId | The param TLSCipherPolicyId is missing. | |
| 400 | TLSPolicyConfiguring | The specified TLS cipher policy is configuring. | |
| 400 | TLSPolicyBeingUsed | The specified TLS cipher policy is being used. | |
| 400 | InvalidTLSPolicyId.NotExist | The specified TLS cipher policy does not exist. | |
| 400 | TLSPolicyUnchanged | The specified TLS cipher policy is unchanged. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.