Gets the details of a specified control policy.
Try it now
Test
RAM authorization
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| InstanceId |
string |
Yes |
The ID of the bastion host instance. Note
You can call the DescribeInstances operation to get this ID. |
bastionhost-cn-zvp2d3syb0g |
| RegionId |
string |
No |
The region ID of the bastion host instance. Note
For more information about region IDs, see Regions and zones. |
cn-hangzhou |
| PolicyId |
string |
Yes |
The ID of the control policy that you want to query. Note
You can call the ListPolicies operation to get this ID. |
3 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| Policy |
object |
The details of the control policy. |
|
| AccessTimeRangeConfig |
object |
The time-based access control settings. |
|
| EffectiveTime |
array<object> |
The allowed access time slots. |
|
|
object |
|||
| Days |
array |
The days of the week when access is allowed. |
|
|
string |
The day of the week. Valid values:
|
[2] |
|
| Hours |
array |
The hours of the day when access is allowed. |
|
|
string |
The hour of the day. Valid values:
|
[0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23] |
|
| CommandConfig |
object |
The command control policy. |
|
| Approval |
object |
The command approval settings. |
|
| Commands |
array |
The commands that require approval. |
|
|
string |
A command that requires approval. |
ls |
|
| Deny |
object |
The command control settings. |
|
| AclType |
string |
The command control mode. Valid values:
|
black |
| Commands |
array |
The commands in the list. |
|
|
string |
The command. |
ls |
|
| Comment |
string |
The remarks on the policy. |
comment |
| IPAclConfig |
object |
The source IP address-based access control settings. |
|
| AclType |
string |
The source IP address-based access control mode. Valid values:
|
black |
| IPs |
array |
The IP addresses in the ACL. |
|
|
string |
An IP address or CIDR block. |
[10.10.**.**] |
|
| PolicyName |
string |
The name of the control policy. |
test |
| PolicyId |
string |
The ID of the control policy. |
3 |
| Priority |
integer |
The priority of the control policy. A smaller value indicates a higher priority. |
1 |
| ProtocolConfig |
object |
The protocol control settings. |
|
| RDP |
object |
The RDP security settings. |
|
| ClipboardDownload |
string |
Indicates whether clipboard download is enabled. Valid values:
|
Enable |
| ClipboardUpload |
string |
Indicates whether clipboard upload is enabled. Valid values:
|
Enable |
| DiskRedirection |
string |
Indicates whether drive redirection and printer mapping are enabled. Valid values:
|
Enable |
| RecordKeyboard |
string |
Indicates whether keyboard recording is enabled. Valid values:
|
Enable |
| DiskRedirectionUpload |
string |
Enable |
|
| DiskRedirectionDownload |
string |
Enable |
|
| SSH |
object |
The SSH and SFTP security settings. |
|
| ExecCommand |
string |
Indicates whether remote command execution is enabled. Valid values:
|
Enable |
| SFTPChannel |
string |
Indicates whether the SFTP channel is enabled. Valid values:
|
Enable |
| SFTPDownloadFile |
string |
Indicates whether file downloads over SFTP are enabled. Valid values:
|
Enable |
| SFTPMkdir |
string |
Indicates whether directory creation over SFTP is enabled. Valid values:
|
Enable |
| SFTPRemoveFile |
string |
Indicates whether file deletion over SFTP is enabled. Valid values:
|
Enable |
| SFTPRenameFile |
string |
Indicates whether file renaming over SFTP is enabled. Valid values:
|
Enable |
| SFTPRmdir |
string |
Indicates whether directory deletion over SFTP is enabled. Valid values:
|
Enable |
| SFTPUploadFile |
string |
Indicates whether file uploads over SFTP are enabled. Valid values:
|
Enable |
| SSHChannel |
string |
Indicates whether the SSH channel is enabled. Valid values:
|
Enable |
| AllowDirectTcp |
string |
Enable |
|
| X11Forwarding |
string |
Indicates whether X11 forwarding is enabled. Valid values:
|
Enable |
| TcpForwarding |
string |
Enable |
|
| AllowTcpForwarding |
string |
Enable |
|
| ApprovalConfig |
object |
The O&M approval settings. |
|
| SwitchStatus |
string |
Indicates whether O&M approval is enabled. Valid values:
|
Off |
| RequestId |
string |
The request ID. |
0D29F2C0-8B4B-5861-9474-F3F23D25594B |
Examples
Success response
JSON format
{
"Policy": {
"AccessTimeRangeConfig": {
"EffectiveTime": [
{
"Days": [
"[2]"
],
"Hours": [
"[0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23]"
]
}
]
},
"CommandConfig": {
"Approval": {
"Commands": [
"ls"
]
},
"Deny": {
"AclType": "black",
"Commands": [
"ls"
]
}
},
"Comment": "comment",
"IPAclConfig": {
"AclType": "black",
"IPs": [
"[10.10.**.**]"
]
},
"PolicyName": "test",
"PolicyId": "3",
"Priority": 1,
"ProtocolConfig": {
"RDP": {
"ClipboardDownload": "Enable",
"ClipboardUpload": "Enable",
"DiskRedirection": "Enable",
"RecordKeyboard": "Enable",
"DiskRedirectionUpload": "Enable",
"DiskRedirectionDownload": "Enable"
},
"SSH": {
"ExecCommand": "Enable",
"SFTPChannel": "Enable",
"SFTPDownloadFile": "Enable",
"SFTPMkdir": "Enable",
"SFTPRemoveFile": "Enable",
"SFTPRenameFile": "Enable",
"SFTPRmdir": "Enable",
"SFTPUploadFile": "Enable",
"SSHChannel": "Enable",
"AllowDirectTcp": "Enable",
"X11Forwarding": "Enable",
"TcpForwarding": "Enable",
"AllowTcpForwarding": "Enable"
}
},
"ApprovalConfig": {
"SwitchStatus": "Off"
}
},
"RequestId": "0D29F2C0-8B4B-5861-9474-F3F23D25594B"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | InvalidParameter | The argument is invalid. | The argument is invalid. |
| 500 | InternalError | An unknown error occurred. | An unknown error occurred. |
| 404 | PolicyNotFound | The policy is not found. | The policy is not found. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.