Security Policy Management
Creating a Security Policy
Operation Steps
-
Go to the Load Balancer ULB page, click Security Policy Management
-
Click Create Security Policy, the creation window for security policy pops up.
-
You need to fill in the following information:
Configuration | Description |
---|---|
Name | Required, the name of the security policy. |
Minimum version of TLS | Required, the minimum supported TLS version, options are TLSv1, TLSv1.1, and TLSv1.2. |
Suite of encryption algorithm | Required, please refer to Security Policy for the supported encryption suites. |
Deleting a Security Policy
Operation Steps
Go to the Load Balancer ULB page, click Security Policy Management.
Security policies bound to VServer and predefined security policies cannot be deleted.
Deleting a Single Security Policy
-
Choose the security policy you want to delete and click Delete.
-
The popup window shows the information of the selected security policy, confirm if it is the one you want to delete.
-
Click Confirm to complete the deletion process.
Deleting Multiple Security Policies
-
Batch select the security policies you want to delete by checking the box on the left, click Delete above.
-
The popup window shows the information of the selected security policies, confirm if they are the ones you want to delete.
-
Click Confirm to complete the deletion process.
Editing a Security Policy
Operation Steps
Go to the Load Balancer ULB page, click Security Policy Management.
Predefined security policies cannot be edited.
Editing a Security Policy
-
Choose the security policy you want to edit and click Edit.
-
Make modifications and click Confirm to complete the operation.
Configuration Instructions
-
Name, Required. If unchanged, the original name will be kept.
-
Minimum version of TLS, Required. If unchanged, the original minimum TLS version will be kept.
-
Suite of encryption algorithm, Required. If unchanged, the original suite of encryption algorithm will be kept.
Binding/Unbinding a Security Policy
The current security policy feature only supports usage in the HTTPS protocol VServer under the request proxy-type CLB.
The security policy feature is currently only in public testing in some regions. If the CLB instance has not yet been publicly tested, it will not be possible to bind or use the created security policy. Please contact technical support if needed.
Binding a Security Policy
-
Enter the VServer Management page, click Add VServer or Change VServer to set VServer configuration.
-
Select HTTPS as the protocol, and click on the dropdown box beside Security Policy to choose a predefined or custom security policy.
Unbinding a Security Policy
-
Enter the VServer Management page, click Change VServer to set VServer configuration.
-
Click on the dropdown box beside Security Policy and choose Native Policy to unbind an already bound predefined or custom security policy. For more information on native policy, refer to Security Policy.
Unbinding All VServers
-
Go to the Load Balancer ULB page, click Security Policy Management.
-
Select the security policy you want to unbind, click Unbind all VServers.
-
The popup window shows the information of the selected security policy, confirm if you want to unbind all VServers of this security policy.
-
Click Confirm to finish the unbinding operation.