sfcb-CIMXML-Processor : Error accepting SSL connection
The ESXi configuration file /etc/sfcb/sfcb.cfg can contain the following configuration tokens which the value can be set to true or false. If no entries are present these are the defaults built into 6.0U3 and 6.5.x.
enableSSLv3: false
enableTLSv1: true
enableTLSv1_1: true
enableTLSv1_2: true
Once these entries are inserted into /etc/sfcb/sfcb.cfg and wbem services are restarted, the new configuration will take effect. For more information, see How to disable or enable the SFCB service (CIM Server) on ESXi host.
Example configuration Small Footprint CIM Broker Daemon (SFCBD) - Port 5989 on 6.0U3
To configure TLS protocols:
/etc/init.d/sfcbd-watchdog start
Example configuration oSmall Footprint CIM Broker Daemon (SFCBD) - Port 5989 on 6.5
To configure TLS protocols:
Managing TLS protocol configuration for vSphere 6.5/6.7
vSphere Client fails to connect to the vCenter Server or ESXi with TLSv1.0 disabled
Impact/Risks:
Allowing SSL protocols considered insecure is not recommended by VMware. SSLv3 previously was disabled by default in 6.0.x release.