VMware Horizon Community
fborges555
Enthusiast
Enthusiast

View 5.1 and TLS 1.1

Hi gurus

I have a view 5,1 environment that will go away in the next 6 -12 month, but at this time I need to enable TLS1.1 and TLS1.2 , as you can see I am still new to vmware, so can anyone that has done this help me with the step by steps on how to accomplish this.

Thanks a bunchhhhhh

0 Kudos
3 Replies
BenFB
Virtuoso
Virtuoso

The last stable release of 5.1 was 5.1.3 which was released on 14 March 2013. The first release where you were able to disable TLS 1.0 and enable TLS 1.1/1.2 is 5.3.6 which was released three years later on 1 March 2016. Even if you could get to View 5.3.6 the versions of vSphere/ESXi that you are running will still require TLS 1.0. Due to the age of this environment and the fact that it's no longer supported I would not advise an upgrade. You should prioritize moving off of this environment ASAP.

VMware Horizon View 5.3.6 Release Notes

As with previous View 5.3.x releases, TLS 1.0 is enabled by default on View servers and the View Composer server. TLS 1.0 is considered insufficiently secure and US-CERT alert TA15-120A recommends disabling TLS 1.0. For View servers, you can configure the security protocols by following the instructions in Configuring Global Acceptance and Proposal Policies in the View Security document. For instructions on how to configure security protocols on the View Composer server, see Microsoft article https://technet.microsoft.com/en-us/library/dn786418.aspx. Note that the versions of vSphere that this View release supports must be patched to enable TLSv1.1/TLSv1.2. If you disable TLS 1.0 on View Composer server or View Connection Server without patching vSphere, View will not be able to communicate with vCenter Server.

Status of TLSv1.1/1.2 Enablement and TLSv1.0 Disablement across VMware products (2145796)

0 Kudos
fborges555
Enthusiast
Enthusiast

BenFB

so No hope for View 5.1 to accomplish this even patching the  locked.property file?

Thanks again for coming through .

0 Kudos
BenFB
Virtuoso
Virtuoso

Even if you can get View to talk TLS 1.1 or 1.2 you also need to be running a vCenter/ESXi version that supports TLS 1.1 or 1.2. Your best bet will be prioritize a much needed move to Horizon 7.x (6.x is going End of Support in just a few months).

0 Kudos