Modifies the attributes of a security policy for a Network Load Balancer (NLB) instance.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
nlb:UpdateSecurityPolicyAttribute |
update |
*SecurityPolicy
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| TlsVersions |
array |
No |
The supported TLS versions. Valid values: TLSv1.0, TLSv1.1, TLSv1.2, and TLSv1.3. You can specify up to four TLS versions. |
|
|
string |
No |
The supported TLS version. Valid values: TLSv1.0, TLSv1.1, TLSv1.2, and TLSv1.3. You can specify up to four TLS versions. |
TLSv1.0 |
|
| SecurityPolicyId |
string |
Yes |
The ID of the TLS security policy. |
tls-bp14bb1e7dll4f**** |
| SecurityPolicyName |
string |
No |
The name of the security policy. The name must be 1 to 200 characters in length, and can contain letters, digits, periods (.), underscores (_), and hyphens (-). |
TLSCipherPolicy |
| Ciphers |
array |
No |
The supported cipher suites. Valid values vary based on the TlsVersions parameter. You can specify up to 32 cipher suites. TLSv1.0 and TLSv1.1 support the following cipher suites:
TLSv1.2 supports the following cipher suites:
TLSv1.3 supports the following cipher suites:
|
|
|
string |
No |
The supported cipher suites. Valid values vary based on the TlsVersions parameter. You can specify up to 32 cipher suites. TLSv1.0 and TLSv1.1 support the following cipher suites:
TLSv1.2 supports the following cipher suites:
TLSv1.3 supports the following cipher suites:
|
ECDHE-ECDSA-AES128-SHA |
|
| RegionId |
string |
No |
The ID of the region where the NLB instance is deployed. You can call the DescribeRegions operation to query the most recent region list. |
cn-hangzhou |
| DryRun |
boolean |
No |
Specifies whether to perform a dry run. Valid values:
|
false |
| ClientToken |
string |
No |
The client token that is used to ensure the idempotence of the request. You can use the client to generate the token. Make sure that the token is unique among different requests. Only ASCII characters are allowed. Note
If you do not specify this parameter, the system uses the value of RequestId as the client token. The value of RequestId is different for each request. |
123e4567-e89b-12d3-a456-426655440000 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID. |
D7A8875F-373A-5F48-8484-25B07A61F2AF |
| SecurityPolicyId |
string |
The ID of the TLS security policy. |
tls-bp14bb1e7dll4f**** |
| JobId |
string |
The ID of the asynchronous task. |
72dcd26b-f12d-4c27-b3af-18f6aed5**** |
Examples
Success response
JSON format
{
"RequestId": "D7A8875F-373A-5F48-8484-25B07A61F2AF",
"SecurityPolicyId": "tls-bp14bb1e7dll4f****",
"JobId": "72dcd26b-f12d-4c27-b3af-18f6aed5****"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | IllegalParam.PreserveClientIpSwitch | The param of PreserveClientIpSwitch is illegal. | |
| 400 | UpdateSecurityPolicyFailed | The operation failed because of Security Policy is not changed. | |
| 404 | ResourceNotFound.securitypolicy | The specified resource of securitypolicy is not found. | |
| 404 | ResourceNotFound.serverGroup | The specified resource of serverGroup is not found. | The specified resource of serverGroup is not found. Please check the input parameters. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.