7.x & 8.x.
To resolve this issue,VMware strongly advises upgrading 3rd party applications so that they use TLS 1.2.
Note: If the user upgrades the ESXi with MD5 config to latest, MD5 config will be removed and user need to update/regenerate their v3 users. For more information see ESXi upgrade operation will trigger a VOB stating "Upgrade detected a weak crypto protocol (MD5)" .
WbemAgentConfig:
Authorization Model: password
CIM Object Manager PID: 0
Enabled: false
Enabled SSL Protocols: <<< -- nothing configured in sfcb.cfg removed on upgrade for SFCB itself
Enabled System SSL Protocols: tls12 <<-- system settings for all VMware Web based services
Log level: warning
Port: 5989
Service Location Protocol PID: 0
WS-Management PID: 0
WS-Management Service: true
# esxlci system wbem set --protocols sslv3,tls1,tls11
# esxcli system wbem get
WbemAgentConfig:
Authorization Model: password
CIM Object Manager PID: 0
Enabled: false
Enabled SSL Protocols: sslv3, tls1, tls11, tls12 <<<== only tcp/5989 now has weak ssl protocols
Enabled System SSL Protocols: tls12
Log level: warning
Port: 5989
Service Location Protocol PID: 0
WS-Management PID: 0
WS-Management Service: true