SV-243112r719579_rule
V-243112
SRG-APP-000516
VCTR-67-000057
CAT II
10
On the vCenter Server, execute the following commands:
# /usr/lib/vmware-vSphereTlsReconfigurator/VcTlsReconfigurator/reconfigureVc backup
# /usr/lib/vmware-vSphereTlsReconfigurator/VcTlsReconfigurator/reconfigureVc update -p TLS1.2
vCenter services will be restarted as part of the reconfiguration, the OS will not be restarted. You can add the --no-restart flag to restart services at a later time. Changes will not take effect until all services are restarted or the machine is rebooted.
Note: For vCenter Server Windows, this is not applicable.
On the vCenter Server, execute the following command:
# /usr/lib/vmware-TlsReconfigurator/VcTlsReconfigurator scan
If the output indicates versions of TLS other than 1.2 are enabled, this is a finding.
V-243112
False
VCTR-67-000057
Note: For vCenter Server Windows, this is not applicable.
On the vCenter Server, execute the following command:
# /usr/lib/vmware-TlsReconfigurator/VcTlsReconfigurator scan
If the output indicates versions of TLS other than 1.2 are enabled, this is a finding.
M
5399