6.7

Table Of Contents
4 If your environment includes other vCenter Server systems, repeat the process on each
vCenter Server system.
5 Repeat the configuration on each ESXi host and each Platform Services Controller.
Enable or Disable TLS Versions on ESXi Hosts
You can use the TLS Configuration utility to enable or disable TLS versions on an ESXi host. As part of
the process, you can disable TLS 1.0, and enable TLS 1.1 and TLS 1.2. Or, you can disable TLS 1.0 and
TLS 1.1, and enable only TLS 1.2.
For ESXi hosts, you use a different utility than for the other components of your vSphere environment.
The utility is release-specific, and cannot be used on a previous release.
Prerequisites
Ensure that any products or services associated with the ESXi host can communicate using TLS 1.1 or
TLS 1.2. For products that communicate only using TLS 1.0, connectivity is lost.
This procedure explains how to perform the task on a single host. You can write a script to configure
multiple hosts.
Procedure
1 Log in to the vCenter Server system with the user name and password of the vCenter Single Sign-On
user who can run scripts.
2 Go to the directory where the script is located.
OS Command
Windows
cd %VMWARE_CIS_HOME%\TlsReconfigurator\EsxTlsReconfigurator
Linux
cd /usr/lib/vmware-TlsReconfigurator/EsxTlsReconfigurator
vSphere Security
VMware, Inc. 230