6.5.1

Table Of Contents
5 Repeat the procedure on any other vCenter Server instances.
6 Repeat the procedure on any other Platform Services Controller instances.
Disable TLS Versions on vSphere Update Manager
In vSphere Update Manager 6.0 Update 3, and later, the TLS protocol versions 1.0, 1.1, and 1.2 are all
enabled by default. You can disable TLS version 1.0 and TLS version 1.1, but you cannot disable TLS
version 1.2.
You can manage the TLS protocol configuration for other services by using the TLS Configuration Utility.
For vSphere Update Manager, however, you must reconfigure the TLS protocol manually.
Modifying the TLS protocol configuration might involve any of the following tasks.
n
Disabling TLS version 1.0 while leaving TLS version 1.1 and TLS version 1.2 enabled.
n
Disabling TLS version 1.0 and TLS version 1.1 while leaving TLS version 1.2 enabled.
n
Re-enabling a disabled TLS protocol version.
Disable Earlier TLS Versions for Update Manager Port 9087
You can disable earlier versions of TLS for port 9087 by modifying the jetty-vum-ssl.xml configuration
file. The process is different for Port 8084.
Note Before you disable a TLS version, make sure that none of the services that communicate with
vSphere Update Manager use that version.
Prerequisites
Stop the vSphere Update Manager service. See the Installing and Administering VMware vSphere
Update Manager documentation.
Procedure
1 Stop the vSphere Update Manager service.
2 Navigate to the Update Manager installation directory, which is different for vSphere 6.0 and vSphere
6.5.
Version Location
vSphere 6.0
C:\Program Files (x86)\VMware\Infrastructure\Update Manager
vSphere 6.5
C:\Program Files\VMware\Infrastructure\Update Manager
3 Make a backup of the jetty-vum-ssl.xml file and open the file.
vSphere Security
VMware, Inc. 221