The SSLv3 support for ESXi 6.0 is disabled by default for all services and ports. You may encounter these errors due to lack of SSLv3 support on these ports:
CIM - Port 5989
The CIM server (sfcbd) stops accepting HTTPS connections and when you run a wbemcli query, you see the error similar to:
[root@galaxy ~]# wbemcli -noverify -cte -nl ei
https://user:[email protected]:5989/root/cimv2:CIM_NumericSensor
*
* wbemcli: Http Exception: SSL connect error
*
[root@galaxy ~]#
In the /var/log/syslog.log file, you see an entry similar to:
<yyyy-mm-dd>T <time>Z sfcb-CIMXML-Processor[nnnnnn]: *** 1920 Error accepting SSL connection -- exiting</time>
SSL Error Stack:
SSL
Note: The preceding log excerpts are only examples. Date, time, and environmental variables may vary depending on your environment.
Authd - Port 902
Linked clone pool creation fails due to connection failure between ESXi 6.0 Update 1 and View Composer 6.1.1 with an error message similar to:
SSLv3 handshake was unsuccessful
See the Solution section to enable the required SSLv3 support to resolve these issues.
Caution: These steps expose the security vulnerabilities with SSLv3. This issue is resolved in VMware View 6.2, available at VMware Downloads. For more information, see VMware Horizon 6 version 6.2 Release Notes.
Follow these steps to enable SSLv3 protocol on hostd service for ESXi 6.0 U1b later.
By default SSLv3 is disabled. If you want to enable SSLv3, set the setting to empty by using the below command:
The SSLv3 support can be enabled for these ports and services: