6.7

Table Of Contents
n
You cannot use a TLS 1.2 only connection to an external Oracle database. See VMware Knowledge
Base article 2149745.
n
Do not disable TLS 1.0 on a vCenter Server or Platform Services Controller instance that is running
on Windows Server 2008. Windows 2008 supports only TLS 1.0. See the Microsoft TechNet Article
TLS/SSL Settings in the Server Roles and Technologies Guide.
n
If you change the TLS protocols, you must restart the ESXi host to apply the changes. You must
restart the host even if you apply the changes through cluster configuration by using host profiles. You
can choose to restart the host immediately, or postpone the restart to a more convenient time.
Enabling or Disabling TLS Versions in vSphere
Disabling TLS versions is a multi-phase process. Disabling TLS versions in the right order ensures that
your environment stays up and running during the process.
1 If your environment includes vSphere Update Manager on Windows, and vSphere Update Manager is
on a separate system, disable protocols explicitly by editing configuration files. See Enable or Disable
TLS Versions on vSphere Update Manager on Windows.
vSphere Update Manager on the vCenter Server Appliance is always included with the
vCenter Server system and the script updates the corresponding port.
2 Run the utility on vCenter Server.
3 Run the utility on each ESXi host that is managed by the vCenter Server. You can perform this task
for each host or for all hosts in a cluster.
4 If your environment uses one or more Platform Services Controller instances, run the utility on each
instance.
Prerequisites
You have two choices for using TLS in your environment.
n
Disable TLS 1.0, and enable TLS 1.1 and TLS 1.2.
n
Disable TLS 1.0 and TLS 1.1, and enable TLS 1.2.
Perform an Optional Manual Backup
The TLS Configuration utility performs a backup each time the script modifies vCenter Server,
Platform Services Controller, or vSphere Update Manager on the vCenter Server Appliance. If you need a
backup to a specific directory, you can perform a manual backup.
Backup of the ESXi configuration is not supported.
For vCenter Server or Platform Services Controller, the default directory differs for Windows and the
appliance.
vSphere Security
VMware, Inc. 227