分組HttpsPolicy的設置
用戶可以再分組上調整API分組所支持的HTTPS安全策略,HTTPS安全策略僅對綁定了域名及證書的分組有效,目前API網關支持HTTPS1_1_TLS1_0
,HTTPS2_TLS1_0
,HTTPS2_TLS1_2
安全策略,但不同Region支持的安全策略列表不同,在控制台->分組詳情
頁可選擇本Region支持的HTTPS安全策略
HTTPS安全策略列表
HTTPS1_1_TLS1_0
- HTTP1.1協議
- 支持TLS v1.0 , TLS v1.1 , TLS v1.2
- 支持加密算法套件:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA:AES128-GCM-SHA256:AES128-SHA256:AES128-SHA:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:AES256-GCM-SHA384:AES256-SHA256:AES256-SHA:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!RC4:!EXPORT:!DES:!3DES:!MD5:!DSS:!PKS;
HTTPS2_TLS1_0
- HTTP2協議, 注意: http2協議會將所有的header轉為小寫
- 支持TLS v1.0 , TLS v1.1 , TLS v1.2
- 支持加密算法套件:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA:AES128-GCM-SHA256:AES128-SHA256:AES128-SHA:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:AES256-GCM-SHA384:AES256-SHA256:AES256-SHA:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!RC4:!EXPORT:!DES:!3DES:!MD5:!DSS:!PKS;
HTTPS2_TLS1_2
- HTTP2協議, 注意: http2協議會將所有的header轉為小寫
- 支持TLS v1.2, 注意: 所有不支持TLS v1.2客戶端將無法建立連接
- 支持加密算法套件:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-RSA-AES256-SHA:!NULL:!aNULL:!MD5:!ADH:!RC4:!DH:!DHE:!3DES;