The NSX-T Manager must disable TLS 1.1 and enable TLS 1.2.
An XCCDF Rule
Description
<VulnDiscussion>TLS 1.0 and 1.1 are deprecated protocols with well-published shortcomings and vulnerabilities. TLS 1.2 must be enabled on all interfaces and TLS 1.1 and 1.0 disabled where supported.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-251798r879588_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Capture the output from the check GET command and update the TLS 1.1 protocol to false.
Execute the following API call using curl or another REST API client:
PUT https://<nsx-mgr>/api/v1/cluster/api-service