すべてのプロダクト
Search
ドキュメントセンター

ApsaraDB RDS:ModifyDBInstanceSSL

最終更新日:Apr 18, 2026

インスタンスの SSL 暗号化設定を変更します。

操作説明

サポートされるデータベースエンジン

  • MySQL

  • PostgreSQL

  • SQL Server

関連ドキュメント

説明

この操作を呼び出す前に、以下のドキュメントをお読みいただき、この操作の前提条件と影響を十分に理解してください。

今すぐお試しください

この API を OpenAPI Explorer でお試しください。手作業による署名は必要ありません。呼び出しに成功すると、入力したパラメーターに基づき、資格情報が組み込まれた SDK コードが自動的に生成されます。このコードをダウンロードしてローカルで使用できます。

テスト

RAM 認証

下表に、この API を呼び出すために必要な認証情報を示します。認証情報は、RAM (Resource Access Management) ポリシーを使用して定義できます。以下で各列名について説明します。

  • アクション:特定のリソースに対して実行可能な操作。ポリシー構文ではAction要素として指定します。

  • API:アクションを具体的に実行するための API。

  • アクセスレベル:各 API に対して事前定義されているアクセスの種類。有効な値:create、list、get、update、delete。

  • リソースタイプ:アクションが作用するリソースの種類。リソースレベルでの権限をサポートするかどうかを示すことができます。ポリシーの有効性を確保するため、アクションの対象として適切なリソースを指定してください。

    • リソースレベルの権限を持つ API の場合、必要なリソースタイプはアスタリスク (*) でマークされます。ポリシーのResource要素で対応する ARN を指定してください。

    • リソースレベルの権限を持たない API の場合、「すべてのリソース」と表示され、ポリシーのResource要素でアスタリスク (*) でマークされます。

  • 条件キー:サービスによって定義された条件のキー。このキーにより、きめ細やかなアクセス制御が可能になります。この制御は、アクション単体に適用することも、特定のリソースに対するアクションに適用することもできます。Alibaba Cloud は、サービス固有の条件キーに加えて、すべての RAM 統合サービスに適用可能な一連の共通条件キーを提供しています。

  • 依存アクション:ある特定のアクションを実行するために、前提として実行が必要となる他のアクション。依存アクションの権限も RAM ユーザーまたは RAM ロールに付与する必要があります。

アクション

アクセスレベル

リソースタイプ

条件キー

依存アクション

rds:ModifyDBInstanceSSL

update

*DBInstance

acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}

  • rds:ResourceTag
  • rds:SSLEnabled
なし

リクエストパラメーター

パラメーター

必須 / 任意

説明

DBInstanceId

string

必須

インスタンス ID。 DescribeDBInstances 操作を呼び出して、インスタンス ID を照会できます。

rm-uf6wjk5****

ConnectionString

string

必須

サーバー証明書を作成または更新する必要がある内部またはパブリックエンドポイント。

rm-uf6wjk5****.mysql.rds.aliyuncs.com

SSLEnabled

integer

任意

SSL 暗号化機能を有効にするか無効にするかを指定します。 有効な値:

  • 1:機能を有効にします。

  • 0:機能を無効にします。

1

CAType

string

任意

サーバー証明書の種類。 このパラメーターは、インスタンスがクラウドディスクで MySQL または PostgreSQL を実行している場合にのみサポートされます。 SSLEnabled を 1 に設定した場合、このパラメーターのデフォルト値は aliyun です。 有効な値:

  • aliyun:クラウド証明書

  • custom:カスタム証明書

aliyun

ServerCert

string

任意

サーバー証明書の内容。 このパラメーターは、インスタンスがクラウドディスクで PostgreSQL を実行している場合にのみサポートされます。 CAType が custom に設定されている場合、このパラメーターを指定する必要があります。

-----BEGIN CERTIFICATE-----MIID*****QqEP-----END CERTIFICATE-----

ServerKey

string

任意

サーバー証明書の秘密鍵。 このパラメーターは、インスタンスがクラウドディスクで PostgreSQL を実行している場合にのみサポートされます。 CAType が custom に設定されている場合、このパラメーターを指定する必要があります。

-----BEGIN PRIVATE KEY-----MIIE****ihfg==-----END PRIVATE KEY-----

ClientCAEnabled

integer

任意

クライアント証明書を発行する CA の公開鍵を有効にするかどうかを指定します。 このパラメーターは、インスタンスがクラウドディスクで PostgreSQL を実行している場合にのみサポートされます。 有効な値:

  • 1:公開鍵を有効にします。

  • 0:公開鍵を無効にします。

1

ClientCACert

string

任意

クライアント証明書を発行する CA の公開鍵。 このパラメーターは、インスタンスがクラウドディスクで PostgreSQL を実行している場合にのみサポートされます。 ClientCAEbabled が 1 に設定されている場合、このパラメーターを指定する必要があります。

-----BEGIN CERTIFICATE-----MIID*****viXk=-----END CERTIFICATE-----

ClientCrlEnabled

integer

任意

失効したクライアント証明書を含む証明書失効リスト (CRL) を有効にするかどうかを指定します。 このパラメーターは、インスタンスがクラウドディスクで PostgreSQL を実行している場合にのみサポートされます。 さらに、このパラメーターは、クライアント証明書を発行する CA の公開鍵が有効になっている場合にのみ使用できます。 有効な値:

  • 1:CRL を有効にします。

  • 0:CRL を無効にします。

1

ClientCertRevocationList

string

任意

失効したクライアント証明書を含む CRL。 このパラメーターは、インスタンスがクラウドディスクで PostgreSQL を実行している場合にのみサポートされます。 ClientCrlEnabled が 1 に設定されている場合、このパラメーターを指定する必要があります。

-----BEGIN X509 CRL-----MIIB****19mg==-----END X509 CRL-----

ACL

string

任意

クライアントの ID を検証するために使用されるメソッド。 このパラメーターは、インスタンスがクラウドディスクで PostgreSQL を実行している場合にのみサポートされます。 さらに、このパラメーターは、クライアント証明書を発行する CA の公開鍵が有効になっている場合にのみ使用できます。 有効な値:

  • cert

  • prefer

  • verify-ca

  • verify-full (インスタンスが PostgreSQL 12 以降を実行している場合にのみサポートされます)

cert

ReplicationACL

string

任意

レプリケーション権限を検証するために使用されるメソッド。 このパラメーターは、インスタンスがクラウドディスクで PostgreSQL を実行している場合にのみサポートされます。 さらに、このパラメーターは、クライアント証明書を発行する CA の公開鍵が有効になっている場合にのみ使用できます。 有効な値:

  • cert

  • prefer

  • verify-ca

  • verify-full (インスタンスが PostgreSQL 12 以降を実行している場合にのみサポートされます)

cert

ForceEncryption

string

任意

強制 SSL 暗号化機能を有効にするかどうかを指定します。 このパラメーターは、ApsaraDB RDS for SQL Server インスタンスでのみサポートされます。 詳細については、「SSL 暗号化機能の設定」をご参照ください。 有効な値:

  • 1:機能を有効にします。

  • 0:機能を無効にします。

1

TlsVersion

string

任意

最小の Transport Layer Security (TLS) バージョン。 有効な値:1.0、1.1、1.2。 このパラメーターは、ApsaraDB RDS for SQL Server インスタンスでのみサポートされます。 詳細については、「SSL 暗号化機能の設定」をご参照ください。

1.1

Certificate

string

任意

カスタム証明書。 カスタム証明書は PFX 形式です。

  • パブリックエンドポイント: oss-<The ID of the region>.aliyuncs.com:<The name of the bucket>:<The name of the certificate file (The file name contains the extension.)>

  • 内部エンドポイント: oss-<The ID of the region>-internal.aliyuncs.com:<The name of the bucket>:<The name of the certificate file (The file name contains the extension.)>

oss-cn-beijing-internal.aliyuncs.com:zhttest:test.pfx

PassWord

string

任意

証明書のパスワード。

zht123456

レスポンスフィールド

フィールド

説明

object

レスポンスパラメーター。

RequestId

string

リクエスト ID。

777C4593-8053-427B-99E2-105593277CAB

成功レスポンス

JSONJSON

{
  "RequestId": "777C4593-8053-427B-99E2-105593277CAB"
}

エラーコード

HTTP ステータスコード

エラーコード

エラーメッセージ

説明

400 InvalidServerCertOrPrivateKey Specify server certificate or private key is invalid.
400 InvalidClientCACert Specify client ca certificate is invalid.
400 InvalidClientCrl Specify client certificate revocation list is invalid.
400 InvalidCAType.NotFound Specify ca type is not found.
400 InvalidACL.NotFound Specify acl is not found.
400 InvalidSSLStatus Specify ssl status is invalid.
400 IncorrectDBSslStatus Specified DB SSLStatus does not support this operation.
400 InvalidModifyMode.Format Specified modify mode is not valid.
400 Order.ComboInstanceNotAllowOperate A package instance is not allowed to operate independently.
400 Price.PricingPlanResultNotFound Pricing plan price result not found.
400 Order.NoRealNameAuthentication You have not passed the real-name authentication and do not meet the purchase conditions. Please log in to the user center for real-name authentication.
400 InsufficientAvailableQuota Your account quota limit is less than 0, please recharge before trying to purchase.
400 CommodityServiceCalling.Exception Failed to call commodity service.
400 RegionDissolvedEOM Dear customer, Alibaba Cloud plans to optimize and adjust the current region. Cloud services in this region will cease operations. You are currently unable to operate new purchase orders. Thank you for your understanding and support.
400 Commodity.InvalidComponent The module you purchased is not legal, please buy it again.
400 RegionEndTimeDissolvedAustralia Cloud services in the Australia (Sydney) region will be discontinued. Set the validity date to September 30, 2024 or earlier than September 30, 2024.
400 Price.CommoditySys Commodity system call exception.
400 Pay.InsufficientBalance Insufficient available balance.
400 Order.PeriodInvalid There is a problem with the period you selected, please choose again.
400 pay.noCreditCard Account not bound to credit card.
400 Order.InstHasUnpaidOrder There is an unpaid order for the service you have purchased. Please pay or void it before placing the order.
400 noAvailablePaymentMethod No payment method is specified for your account. We recommend that you add a payment method.
400 BasicInfoUncompleted Your information is incomplete. Complete your information before the operation.
400 Risk.RiskControlRejection Your account is abnormal, please contact customer service for details.
400 Api.NotSupport Specified api is not supported.
400 ContainForbiddenLabelError There is a label that prohibits placing orders. Please contact your distributor for assistance.
400 InvalidDBInstanceId.NotFound The DBInstanceId provided does not exist in records.
400 InvalidInstanceLevel.DiskType Specified instance level not support request disk type
400 InvalidParam Sepcified wal level Parameter is invalid. There are still logical slots in instance, so it can not be set as replica.
400 KmsApiError User secret key invalid.
400 System.SaleValidateFailed Sales expression validation system error.
400 Abs.InvalidAccount.NotFound account is not found.
400 SqlExecuteFailedOrTimeout sql command execution failed or timed out:%s.
400 ColdData.EngineVersionNotSupport The current instance engine version not support coldDataEnabled.
400 ColdData.MinorVersionNotSupport The current instance minor version not support coldDataEnabled.
400 IncorrectTargetClasscode The current instance type does not support this operation.
400 InvalidConnectionString.Duplicate Specified connection string already exists in the RDS.
400 RequiredParam.NotFound Required input param is not found.
400 Parameters.Invalid Parameter error, please check the parameters.
400 BackupPolicyNotSupport Cold Data won't open with CrossBackup or Flash Backup, please check Backup Policy.
400 InvalideStatus.Format The instance status does not support this operation.
400 InvalidReleasedKeepPolicy.Format Specified Released Keep Policy is not valid.
400 InvalidDBInstanceEngineType.Format the DB instance engine type does not support this operation.
400 Pay.NoCreditCard No credit cards.
400 VpcNetworkTypeNotSupport The vpc network type instance does not support this operation.
400 MirrorInsExists Specified DB instance mirror ins already existed.
400 UnsupportedClassCode The specified DB instance class stops selling.
400 InvalidBackupSet The specified database does not exist in the backup set.
400 OrdTCommodityQueryError Failed to query for product.
400 ProductInstanceReleased The instance has been released. Please check before placing the order.
400 RegionEndTimeDissolvedIndia The region is no longer supported.
400 MinorVersionNotSupport.SSLEnabled Custins minor version does not support current action.
500 ExternalFailure The request processing has failed due to external service failure.
500 RequestMetaDataFailed The service request failed. Please try again later or contact service personnel.
500 InvokeProxyFailure The request processing has failed due to service failure of rds api.
403 InvalidClientCrl.Permission Client ca certificate is set first if need to set client certificate revocation list.
403 InvalidACL.Permission Client ca certificate is set first if need to set acl.
403 OrderStatus.UnPaid The specified db instance has unpaid order.
403 InvalidReduceDiskSize The storage capacity after the scale-down must be larger than the used amount.
403 CloudSSDNotSupport Cloud ssd does not support this operation, please upgrade to essd.
403 InvalidUserOperatorPermission The user permission does not support this operation.
403 InvalidVswitchId Specified conn vswitch id is not valid.
403 IncorrectMinorVersion Current engine minor version does not support operations.
403 OperationDenied.ZoneResource There is no available zone for inventory.
403 NotInFlowController Sorry,no permission.
403 InvalidKmsKey Kms key is disabled.
403 InvalidInstanceLevel.Malformed Current DB instance level does not support this operation.
403 MaxscaleMinorVersionNotSupport The Maxscale version used by the instance is too low, please upgrade the Maxscale version first.
403 UnsupportedByBlueGreenDeployment Operation prohibited due to blue green deployment.
404 Endpoint.NotFound Specified endpoint is not existed.
404 InvalidClusterKms The current instance does not authorized to access the Key Management Service.
404 Request.NotFound The requested resource is not available.
404 HostInfo.NotFound The specified host info is not found.

完全なリストについては、「エラーコード」をご参照ください。

変更履歴

完全なリストについては、「変更履歴」をご参照ください。