tencent cloud

APIs

ModifySecurityPolicyAttributes

다운로드
포커스 모드
폰트 크기
마지막 업데이트 시간: 2026-09-28 14:17:22

1. API Description

Domain name for API request: alb.intl.tencentcloudapi.com.

Modify the properties of a custom security policy, including the policy name, TLS protocol version, and encryption suite. The modified configuration will be applied to all HTTPS listeners associated with this policy immediately.

A maximum of 20 requests can be initiated per second for this API.

We recommend you to use API Explorer
Try it
API Explorer provides a range of capabilities, including online call, signature authentication, SDK code generation, and API quick search. It enables you to view the request, response, and auto-generated examples.

2. Input Parameters

The following request parameter list only provides API request parameters and some common parameters. For the complete common parameter list, see Common Request Parameters.

Parameter Name Required Type Description
Action Yes String Common Params. The value used for this API: ModifySecurityPolicyAttributes.
Version Yes String Common Params. The value used for this API: 2025-10-30.
Region Yes String Common Params. For more information, please see the list of regions supported by the product.
SecurityPolicyId Yes String

Security policy ID, format: tls- followed by 8 alphanumeric characters.

Ciphers.N No Array of String

Modified encryption suite list. The encryption suite is used to negotiate the encryption algorithm between client and server.

Configuration instructions:

  • The optional range of encryption suites depends on the selected TLS protocol version (TLSVersions parameter).
  • As long as an encryption suite is supported by any one of the selected TLS versions, it can be added to the list.
  • If TLSVersions contains TLSv1.3: TLSv1.3 exclusive encryption suites can be unspecified (the system will auto-complete all TLSv1.3 suites); if specified, all TLSv1.3 exclusive encryption suites must be included. Specifying only part is not supported.

Get available encryption suites:
Call the DescribeSecurityPolicyCapabilities API to query the encryption suite list supported by each TLS version.

Note: If this parameter is not specified, the original configuration remains unchanged.

DryRun No Boolean

Whether to only execute a preflight request. Values:

  • true: Only execute a preflight request without actually modifying resources. The preflight request will verify parameter format, permission, and configuration validity, helping you identify potential issues before proceeding with any operations.
  • false (default): Execute a normal request. After passing the preflight, the security policy will be directly modified.
SecurityPolicyName No String

Modified security policy name, used to identify and distinguish different security policies.

Naming rule:

  • Length: 2–128 characters.
  • Must start with English letters or Chinese characters.
  • Can contain English letters, Chinese characters, digits, half-width periods (.), underscores (_), and dashes (-).

Note: If this parameter is not specified, the original name remains unchanged.

TLSVersions.N No Array of String

List of TLS protocol versions after modification. TLS (Transport Layer Security) is used to guarantee the security of communication between clients and the load balancer.

Available values:

  • TLSv1.0: Best compatibility, but low security level. Not recommended for production environment.
  • TLSv1.1: Slightly better security than TLSv1.0, but still not recommended.
  • TLSv1.2: Current mainstream security protocol version, balancing security and compatibility.
  • TLSv1.3: Latest version, highest security and better performance. Recommended to prioritize.

Note:

  • If this parameter is not specified, the original configuration remains unchanged.
  • When modifying the TLS version, check whether the Ciphers parameter configuration is compatible.

3. Output Parameters

Parameter Name Type Description
RequestId String The unique request ID, generated by the server, will be returned for every request (if the request fails to reach the server for other reasons, the request will not obtain a RequestId). RequestId is required for locating a problem.

4. Example

Example1 Modify a security policy

Input Example

POST / HTTP/1.1
Host: alb.intl.tencentcloudapi.com
Content-Type: application/json
X-TC-Action: ModifySecurityPolicyAttributes
<Common request parameters>

{
    "Ciphers": [
        "TLS_AES_128_GCM_SHA256"
    ],
    "SecurityPolicyId": "tls-t2ckydug",
    "SecurityPolicyName": "test-policy2",
    "TLSVersions": [
        "TLSv1.1",
        "TLSv1.2"
    ]
}

Output Example

{
    "Response": {
        "RequestId": "3b848733-70e5-4558-ae39-4b9938eb7609"
    }
}

5. Developer Resources

SDK

TencentCloud API 3.0 integrates SDKs that support various programming languages to make it easier for you to call APIs.

Command Line Interface

6. Error Code

The following only lists the error codes related to the API business logic. For other error codes, see Common Error Codes.

Error Code Description
AuthFailure CAM signature/authentication error.
DryRunOperation DryRun operation means the request will be successful, but the DryRun parameter is passed.
FailedOperation Operation failed.
InternalError Internal error.
InvalidParameter Parameter error.
InvalidParameterValue Parameter value error.
LimitExceeded The quota limit is exceeded.
MissingParameter Parameters are missing.
OperationDenied Operation denied.
RegionError Region error
RequestLimitExceeded Number of requests exceeds the frequency limit.
UnauthorizedOperation Unauthorized operation.
UnknownParameter Unknown parameter error.
UnsupportedOperation The operation is not supported.

도움말 및 지원

문제 해결에 도움이 되었나요?

피드백