Mendapatkan detail kebijakan kontrol yang ditentukan.
Coba sekarang
Test
RAM authorization
Parameter permintaan
|
Parameter |
Type |
Required |
Description |
Example |
| InstanceId |
string |
Yes |
ID instance bastion host. Catatan
Anda dapat memanggil operasi DescribeInstances untuk mendapatkan ID ini. |
bastionhost-cn-zvp2d3syb0g |
| RegionId |
string |
No |
ID region instance bastion host. Catatan
Untuk informasi lebih lanjut tentang ID region, lihat Region dan zona. |
cn-hangzhou |
| PolicyId |
string |
Yes |
ID kebijakan kontrol yang ingin Anda kueri. Catatan
Anda dapat memanggil operasi ListPolicies untuk mendapatkan ID ini. |
3 |
Elemen respons
|
Element |
Type |
Description |
Example |
|
object |
|||
| Policy |
object |
Detail kebijakan kontrol. |
|
| AccessTimeRangeConfig |
object |
Pengaturan kontrol akses berbasis waktu. |
|
| EffectiveTime |
array<object> |
The details of the periods during which logons are allowed. |
|
|
object |
|||
| Days |
array |
The days of a week on which logons are allowed. |
|
|
string |
The day of the week during which logons are allowed. Valid values:
|
[2] |
|
| Hours |
array |
The time periods during which logons are allowed. |
|
|
string |
The periods of the day during which logons are allowed. Valid values:
|
[0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23] |
|
| CommandConfig |
object |
Kebijakan kontrol perintah. |
|
| Approval |
object |
The details of the command approval settings. |
|
| Commands |
array |
An array of commands that can be run only after approval. |
|
|
string |
The command that can be run only after approval. |
ls |
|
| Deny |
object |
The details of the command control setting. |
|
| AclType |
string |
The type of command control. Valid values:
|
black |
| Commands |
array |
An array of controlled commands. |
|
|
string |
The controlled command. |
ls |
|
| Comment |
string |
Keterangan pada kebijakan. |
comment |
| IPAclConfig |
object |
Pengaturan kontrol akses berbasis alamat IP sumber. |
|
| AclType |
string |
The mode of access control on source IP addresses. Valid values:
|
black |
| IPs |
array |
The IP addresses from which logons are not allowed. |
|
|
string |
The controlled IP addresses. |
[10.10.**.**] |
|
| PolicyName |
string |
Nama kebijakan kontrol. |
test |
| PolicyId |
string |
ID kebijakan kontrol. |
3 |
| Priority |
integer |
Prioritas kebijakan kontrol. Nilai yang lebih kecil menunjukkan prioritas yang lebih tinggi. |
1 |
| ProtocolConfig |
object |
Pengaturan kontrol protokol. |
|
| RDP |
object |
The configuration details of Remote Desktop Protocol (RDP) options. |
|
| ClipboardDownload |
string |
Indicates whether downloading from the clipboard is enabled. Valid values:
|
Enable |
| ClipboardUpload |
string |
Indicates whether file uploading from the clipboard is enabled. Valid values:
|
Enable |
| DiskRedirection |
string |
Indicates whether driver mapping is enabled. Valid values:
|
Enable |
| RecordKeyboard |
string |
Indicates whether keyboard recording is enabled. Valid values:
|
Enable |
| DiskRedirectionUpload |
string |
Enable |
|
| DiskRedirectionDownload |
string |
Enable |
|
| SSH |
object |
The configuration details of SSH and SSH File Transfer Protocol (SFTP) options. |
|
| ExecCommand |
string |
Indicates whether remote command execution is enabled. Valid values:
|
Enable |
| SFTPChannel |
string |
Indicates whether the SFTP channel option is enabled. Valid values:
|
Enable |
| SFTPDownloadFile |
string |
Indicates whether file downloading is enabled in SFTP-based O&M. Valid values:
|
Enable |
| SFTPMkdir |
string |
Indicates whether folder creation is enabled in SFTP-based O&M. Valid values:
|
Enable |
| SFTPRemoveFile |
string |
Indicates whether file deletion is enabled in SFTP-based O&M. Valid values:
|
Enable |
| SFTPRenameFile |
string |
Indicates whether file renaming is enabled in SFTP-based O&M. Valid values:
|
Enable |
| SFTPRmdir |
string |
Indicates whether folder deletion is enabled in SFTP-based O&M. Valid values:
|
Enable |
| SFTPUploadFile |
string |
Indicates whether file uploading is enabled in SFTP-based O&M. Valid values:
|
Enable |
| SSHChannel |
string |
Indicates whether the SSH channel option is enabled. Valid values:
|
Enable |
| AllowDirectTcp |
string |
Enable |
|
| X11Forwarding |
string |
Indicates whether X11 forwarding is enabled. Valid values:
|
Enable |
| TcpForwarding |
string |
Enable |
|
| AllowTcpForwarding |
string |
Enable |
|
| ApprovalConfig |
object |
Pengaturan persetujuan O&M. |
|
| SwitchStatus |
string |
Indicates whether O&M approval is enabled in the control policy. Valid values:
|
Off |
| RequestId |
string |
ID permintaan. |
0D29F2C0-8B4B-5861-9474-F3F23D25594B |
Contoh
Respons sukses
JSONformat
{
"Policy": {
"AccessTimeRangeConfig": {
"EffectiveTime": [
{
"Days": [
"[2]"
],
"Hours": [
"[0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23]"
]
}
]
},
"CommandConfig": {
"Approval": {
"Commands": [
"ls"
]
},
"Deny": {
"AclType": "black",
"Commands": [
"ls"
]
}
},
"Comment": "comment",
"IPAclConfig": {
"AclType": "black",
"IPs": [
"[10.10.**.**]"
]
},
"PolicyName": "test",
"PolicyId": "3",
"Priority": 1,
"ProtocolConfig": {
"RDP": {
"ClipboardDownload": "Enable",
"ClipboardUpload": "Enable",
"DiskRedirection": "Enable",
"RecordKeyboard": "Enable",
"DiskRedirectionUpload": "Enable",
"DiskRedirectionDownload": "Enable"
},
"SSH": {
"ExecCommand": "Enable",
"SFTPChannel": "Enable",
"SFTPDownloadFile": "Enable",
"SFTPMkdir": "Enable",
"SFTPRemoveFile": "Enable",
"SFTPRenameFile": "Enable",
"SFTPRmdir": "Enable",
"SFTPUploadFile": "Enable",
"SSHChannel": "Enable",
"AllowDirectTcp": "Enable",
"X11Forwarding": "Enable",
"TcpForwarding": "Enable",
"AllowTcpForwarding": "Enable"
}
},
"ApprovalConfig": {
"SwitchStatus": "Off"
}
},
"RequestId": "0D29F2C0-8B4B-5861-9474-F3F23D25594B"
}
Kode kesalahan
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | InvalidParameter | The argument is invalid. | |
| 500 | InternalError | An unknown error occurred. | |
| 404 | PolicyNotFound | The policy is not found. |
Lihat Error Codes untuk daftar lengkap.
Catatan rilis
Lihat Release Notes untuk daftar lengkap.