ESXi: 7.0
TCI: 2.2
Ensure external storage array management endpoints, VASA Providers, and REST APIs are configured to support TLS 1.2.
Verify the configured disabled TLS protocols on an ESXi host by executing the following ESXCLI command:
esxcli system settings advanced list -o /UserVars/ESXiVPsDisabledProtocols
If communication with legacy storage systems requiring TLS 1.0 or TLS 1.1 is necessary, use the vSphere TLS Reconfigurator utility (tls_configurator) on the ESXi host to re-enable legacy protocols.
Do not enforce TLS 1.3 exclusively on backend storage controllers, as ESXi 7.x hosts do not support TLS 1.3 protocol negotiation.