v1

latestOpenAPI 3.0.0Creative Commons Attribution 3.02026-07-131,0021,0174.3 MB
sslPolicies

Patches the specified SSL policy with the data included in the request.

patch/projects/{project}/global/sslPolicies/{sslPolicy}

Path parameters

projectstring required

Project ID for this request.

sslPolicystring required

Name of the SSL policy to update. The name must be 1-63 characters long, and comply with RFC1035.

Query parameters

requestIdstring

An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed.

For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments.

The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).

Request body

kindstring

Output only. [Output only] Type of the resource. Alwayscompute#sslPolicyfor SSL policies.

minTlsVersion'TLS_1_0' | 'TLS_1_1' | 'TLS_1_2' | 'TLS_1_3'

The minimum version of SSL protocol that can be used by the clients to establish a connection with the load balancer. This can be one ofTLS_1_0, TLS_1_1, TLS_1_2,TLS_1_3. When set to TLS_1_3, the profile field must be set to RESTRICTED.

namestring

Name of the resource. The name must be 1-63 characters long, and comply with RFC1035. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash.

enabledFeaturesstring[]

Output only. [Output Only] The list of features enabled in the SSL policy.

fingerprintstring byte

Fingerprint of this resource. A hash of the contents stored in this object. This field is used in optimistic locking. This field will be ignored when inserting a SslPolicy. An up-to-date fingerprint must be provided in order to update the SslPolicy, otherwise the request will fail with error 412 conditionNotMet.

To see the latest fingerprint, make a get() request to retrieve an SslPolicy.

descriptionstring

An optional description of this resource. Provide this property when you create the resource.

regionstring

Output only. [Output Only] URL of the region where the regional SSL policy resides. This field is not applicable to global SSL policies.

customFeaturesstring[]

A list of features enabled when the selected profile is CUSTOM. The method returns the set of features that can be specified in this list. This field must be empty if the profile is notCUSTOM.

creationTimestampstring

Output only. [Output Only] Creation timestamp inRFC3339 text format.

postQuantumKeyExchange'DEFAULT' | 'DEFERRED' | 'ENABLED'

One of DEFAULT, ENABLED, orDEFERRED. Controls whether the load balancer negotiates X25519MLKEM768 key exchange when clients advertise support for it. When set to DEFAULT, or if no SSL Policy is attached to the target proxy, the load balancer disallows X25519MLKEM768 key exchange before October 2026, and allows it afterward. When set to ENABLED, the load balancer allows X25519MLKEM768 key exchange. When set toDEFERRED, the load balancer disallows X25519MLKEM768 key exchange until October 2027, and allows it afterward.

selfLinkstring

Output only. [Output Only] Server-defined URL for the resource.

profile'COMPATIBLE' | 'CUSTOM' | 'FIPS_202205' | 'MODERN' | 'RESTRICTED'

Profile specifies the set of SSL features that can be used by the load balancer when negotiating SSL with clients. This can be one ofCOMPATIBLE, MODERN, RESTRICTED,FIPS_202205, or CUSTOM. If usingCUSTOM, the set of SSL features to enable must be specified in the customFeatures field. If using FIPS_202205, the min_tls_version field must be set to TLS_1_2.

idstring uint64

Output only. [Output Only] The unique identifier for the resource. This identifier is defined by the server.

Response

Successful response