After you install NSX-T Data Center, the manager nodes and cluster have self-signed certificates.
If you are using Federation, additional certificates are set up to establish trust between the Local Managers and Global Manager.
You can import certificates, create a certificate signing request (CSR), generate self-signed certificates, and import a certificate revocation list (CRL). To improve security, it is recommended that you replace the self-signed certificates with CA-signed certificates.