After enabling TLS (Transport Layer Security) version 1.1 or 1.2, the clients in your environment become disconnected with the following error:
Other possible errors:
In the communication profile. appropriate TLS Versions are not checked/enabled
or
Transport Layer Security (TLS) is not completely enabled on the Symantec Management Platform server. Allow agent and server to both use the same TLS algorithms. This is often caused by the agent profile only having TLS 1.0 checked and the agent operating system only allowing TLS 1.2.
Windows Server 2008 R2 and possibly Window Server 2012
First in the console, check the communication profile which agent tries to connect and make sure the appropriate TLS options are enabled:
If that was checked, then:
Reference Microsoft article: https://technet.microsoft.com/en-us/library/dn786418.aspx
You will notice this article indicates that you need to create a registry key for TLS version 1.1 or/and 1.2 based upon your desired protocol. While the article also references TLS 1.0, errors are not experienced when using 1.0.
As per the linked Microsoft article, on your SMP, open the registry and do the following:
To verify this you should reference the following registry key to make sure it exists:
Related Issues:
CEM Clients receive connection error with TLS 1.1 or 1.2 but connect successfully with TLS 1.0
Additional Microsoft Forum posts with resolution possibilities: