6.5.1

Table Of Contents
Managing TLS Protocol
Configuration with the TLS
Configurator Utility 10
By default, the TLS protocol versions 1.0, 1.1, and 1.2 are enabled in vSphere. You can use the TLS
Configurator Utility to enable or disable TLS protocol versions. You can disable TLS 1.0, or you can
disable both TLS 1.0 and TLS 1.1.
Before you perform reconfiguration, consider your environment.
n
Ensure that vCenter Server, Platform Services Controller, vSphere Update Manager and ESXi hosts
within the environment are running software versions that support disabling TLS versions. See
VMware Knowledge Base article 2145796 for a list of VMware products that support disabling TLS
1.0.
n
Ensure that other VMware products and third-party products support a TLS protocol that is enabled.
Depending on your configuration, that can be TLS 1.2 or both TLS 1.1 and TLS 1.2.
This section includes the following topics:
n
Ports That Support Disabling TLS Versions
n
Disabling TLS Versions in vSphere
n
Install the TLS Configuration Utility
n
Perform an Optional Manual Backup
n
Disable TLS Versions on vCenter Server Systems
n
Disable TLS Versions on ESXi Hosts
n
Disable TLS Versions on Platform Services Controller Systems
n
Revert TLS Configuration Changes
n
Disable TLS Versions on vSphere Update Manager
Ports That Support Disabling TLS Versions
When you run the TLS Configurator utility in the vSphere environment, you can disable TLS across ports
that use TLS on vCenter Server, Platform Services Controller, and ESXi hosts. You can disable TLS 1.0
or both TLS 1.0 and TLS 1.1.
The following table lists the ports. If a port is not included, the utility does not affect it.
VMware, Inc.
209