6.5.1

Table Of Contents
Disable TLS Versions on ESXi Hosts
You can use the TLS Configuration utility to disable TLS versions on an ESXi host. As part of the process,
you can either enable both TLS 1.1 and TLS 1.2, or enable only TLS 1.2.
For ESXi hosts, you use a different script than for the other components of your vSphere environment.
Note The script disables both TLS 1.0 and TLS 1.1 unless you specify the -p option.
Prerequisites
Ensure that any products or services associated with the ESXi host can communicate using TLS 1.1 or
TLS 1.2. For products that communicate only using TLS 1.0, connectivity is lost.
This procedure explains how to perform the task on a single host. You can write a script to configure
multiple hosts.
Procedure
1 Log in to the ESXi host as a user who can run scripts and go to the directory where the script is
located.
OS Command
Windows
cd ..\EsxTlsReconfigurator
Linux
cd ../EsxTlsReconfigurator
vSphere Security
VMware, Inc. 216