Skip to content

The NSX-T Manager must disable TLS 1.1 and enable TLS 1.2.

An XCCDF Rule

Description

TLS 1.0 and 1.1 are deprecated protocols with well-published shortcomings and vulnerabilities. TLS 1.2 must be enabled on all interfaces and TLS 1.1 and 1.0 disabled where supported.

ID
SV-251798r879588_rule
Version
TNDM-3X-000101
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Capture the output from the check GET command and update the TLS 1.1 protocol to false.

Execute the following API call using curl or another REST API client:

PUT https://<nsx-mgr>/api/v1/cluster/api-service