6.5.1

Table Of Contents
<ssl>
<privateKey>ssl/rui.key</privateKey>
<certificate>ssl/rui.crt</certificate>
<sslOptions>sslOptions_value</sslOptions>
</ssl>
5 Depending on the TLS version that you want to disable, use one of the following decimal values in the
<sslOptions> tag.
n
To disable only TLSv1.0, use the decimal value 117587968.
n
To disable TLSv1.0 and TLSv1.1, use the decimal value 386023424
6 Save the file.
7 Restart the vSphere Update Manager service.
Reenable Disabled TLS Versions for Update Manager Port 9087
If you disable a version of TLS for Update Manager Port 9087 and you encounter problems, you can
reenable the version. The process is different for reenabling port 8084.
Reenabling an earlier version of TLS has security implications.
Procedure
1 Stop the vSphere Update Manager service.
2 Navigate to the Update Manager installation directory which is different for 6.0 and 6.5.
Version Location
vSphere 6.0
C:\Program Files (x86)\VMware\Infrastructure\Update Manager
vSphere 6.5
C:\Program Files\VMware\Infrastructure\Update Manager
3 Make a backup of the jetty-vum-ssl.xml file and open the file.
4 Remove the TLS tag that corresponds to the TLS protocol version that you want to enable.
For example, remove <Item>TLSv1.1</Item> in the jetty-vum-ssl.xml file to enable TLSv1.1.
5 Save the file.
6 Restart the vSphere Update Manager service.
Reenable Disabled TLS Versions for Update Manager Port 8084
If you disable a version of TLS for Update Manager Port 8084 and you encounter problems, you can
reenable the version. The process is different for port 9087.
Reenabling an earlier version of TLS has security implications.
Procedure
1 Stop the vSphere Update Manager service.
vSphere Security
VMware, Inc. 223