TECHNICAL WHITE PAPER / 11
l
Must be usable for client authentication
l
Must be issued by any Collector Certificate issued by the Enterprise Certificate, known to the Agent
TLS Machine Security Level
Once the Collector establishes communication with an Agent using TLS, the Collector does not permit HTTP
communication without it. To do so would allow a malicious actor to impersonate either the Collector or Agent by
downgrading the communication security level.
The restrictions concerning the establishment of Server Authentication and Mutual Authentication relationships are:
l
Once an agent has established Server Authentication, the Collector will not allow non-TLS HTTP com-
munication.
l
Once an agent has established Mutual Authentication, the Collector will not allow non-TLS HTTP or Server
(only) Authenticated TLS communication.
l
The Collector supports both TLS and non-TLS capable Agents from earlier releases. Please contact VMware
Customer Support for assistance using the current release with earlier Agents (TLS and non-TLS enabled).
These restrictions do not apply to DCOM. The Security level persists across change protocol and installation/upgrade
actions.
TLS Implementation for VCM