The latest advise from RFCs are to disable TLSv1.0 along with SSLv2, v3; deprecate TLSv1.1 and have TLS v1.2 by default, support TLSv1.3 as well:
https://datatracker.ietf.org/doc/html/rfc8446
https://datatracker.ietf.org/doc/html/rfc8996
Given we support legacy hypervisors, we can't do this by default. This should change and be considered in near future as and when XS7.1 along with VMware 6.0, 6.5 reach EOL.
ISSUE TYPE
COMPONENT NAME
TLS, connections, security
Old PR for reference: #5823