tencent cloud

APIs

CreateSecurityPolicy

ダウンロード
フォーカスモード
フォントサイズ
最終更新日: 2026-09-28 14:17:32

1. API Description

Domain name for API request: alb.intl.tencentcloudapi.com.

Create a custom security policy for configuring the TLS protocol version and encryption suite of an HTTPS listener. With a security policy, you can flexibly control the security level of HTTPS communication between clients and load balancing.

A maximum of 20 requests can be initiated per second for this API.

We recommend you to use API Explorer
Try it
API Explorer provides a range of capabilities, including online call, signature authentication, SDK code generation, and API quick search. It enables you to view the request, response, and auto-generated examples.

2. Input Parameters

The following request parameter list only provides API request parameters and some common parameters. For the complete common parameter list, see Common Request Parameters.

Parameter Name Required Type Description
Action Yes String Common Params. The value used for this API: CreateSecurityPolicy.
Version Yes String Common Params. The value used for this API: 2025-10-30.
Region Yes String Common Params. For more information, please see the list of regions supported by the product.
Ciphers.N Yes Array of String

List of encryption suites supported by the security policy. Encryption suites are used to negotiate the encryption algorithm between client and server.

Configuration instructions:

  • The optional range of encryption suites depends on the selected TLS protocol version (TLSVersions parameter).
  • An encryption suite can be added to the list as long as it is supported by any one of the selected TLS versions.
  • If TLSVersions includes TLSv1.3: you can add TLSv1.3 exclusive encryption suites without specifying them (the system will auto-complete all TLSv1.3 suites); if specified, all TLSv1.3 exclusive encryption suites must be included. Specifying only part of them is not supported.

Get available encryption suites:
Call the DescribeSecurityPolicyCapabilities API to query the encryption suite list supported by each TLS version.

TLSVersions.N Yes Array of String

List of TLS protocol versions supported by the security policy. TLS (Transport Layer Security) is used to ensure communication security between clients and load balancing.

Available values:

  • TLSv1.0: Best compatibility, but low security level. Not recommended for production environment.
  • TLSv1.1: Slightly better security than TLSv1.0, but still not recommended.
  • TLSv1.2: Current mainstream security protocol version, balancing security and compatibility.
  • TLSv1.3: Latest version with the highest security and better performance. Recommended for priority use.

Recommendation: For production environment, at least select TLSv1.2. If client support is available, preferentially enable TLSv1.3.

ClientToken No String

Client idempotency token.

Used for ensuring request idempotency and preventing duplicate creation caused by network timeout or client retry. We recommend using a UUID as the token value. When the same ClientToken is used for repeated requests within its validity period, the server will return the same result.

DryRun No Boolean

Whether to only execute a preflight request. Values:

  • true: Only execute a preflight request without creating resources. The preflight request will verify parameter format, permission, and resource quota, helping you identify potential issues before proceeding with any operations.
  • false (default): Execute a normal request. After the preflight passes, a security policy will be created directly.
SecurityPolicyName No String

security policy name. Used to identify and distinguish different security policies.

Naming rule:

  • 2–128 characters in length.
  • Must start with English letters or Chinese characters.
  • Can contain English letters, Chinese characters, digits, half-width periods (.), underscores (_), and dashes (-).

Recommendation: Use a name with business meaning, such as "prod-high-security" or "test environment policy".

Tags.N No Array of TagInfo

Tag list of the security policy. Tags are used for resource classification and management, making it easy to filter and organize resources by business, environment, department, and other dimensions.

Each tag consists of a Key-Value pair, and tag keys cannot be repeated under the same resource.

3. Output Parameters

Parameter Name Type Description
SecurityPolicyId String

Security policy ID, format: tls- followed by 8 alphanumeric characters.

RequestId String The unique request ID, generated by the server, will be returned for every request (if the request fails to reach the server for other reasons, the request will not obtain a RequestId). RequestId is required for locating a problem.

4. Example

Example1 Creating a Custom Security Policy

Input Example

POST / HTTP/1.1
Host: alb.intl.tencentcloudapi.com
Content-Type: application/json
X-TC-Action: CreateSecurityPolicy
<Common request parameters>

{
    "Ciphers": [
        "TLS_AES_128_GCM_SHA256"
    ],
    "SecurityPolicyName": "test-policy",
    "TLSVersions": [
        "TLSv1.2",
        "TLSv1.3"
    ],
    "Tags": [
        {
            "TagKey": "key-xxx",
            "TagValue": "value-xxx"
        }
    ]
}

Output Example

{
    "Response": {
        "SecurityPolicyId": "tls-t2ckydug",
        "RequestId": "3b848733-70e5-4558-ae39-4b9938eb7609"
    }
}

5. Developer Resources

SDK

TencentCloud API 3.0 integrates SDKs that support various programming languages to make it easier for you to call APIs.

Command Line Interface

6. Error Code

The following only lists the error codes related to the API business logic. For other error codes, see Common Error Codes.

Error Code Description
AuthFailure CAM signature/authentication error.
DryRunOperation DryRun operation means the request will be successful, but the DryRun parameter is passed.
FailedOperation Operation failed.
InternalError Internal error.
InvalidParameter Parameter error.
InvalidParameter.InvalidFieldValue Field value is incorrect.
InvalidParameterValue Parameter value error.
LimitExceeded The quota limit is exceeded.
MissingParameter Parameters are missing.
OperationDenied Operation denied.
RegionError Region error
RequestLimitExceeded Number of requests exceeds the frequency limit.
UnauthorizedOperation Unauthorized operation.
UnknownParameter Unknown parameter error.
UnsupportedOperation The operation is not supported.

ヘルプとサポート

この記事はお役に立ちましたか?

フィードバック