Because the vCenter Single Sign-On Security Token Service (STS) signing certificate is an internal VMware certificate, do not replace it unless your company mandates the replacement of internal certificates. If you want to replace the default STS signing certificate, you must first generate a new certificate and add it to the Java key store. This procedure explains the steps on a Windows installation.
Note: This certificate is valid for ten years and is not an external-facing certificate. Do not replace this certificate unless your company's security policy requires it.
See Generate a New STS Signing Certificate on the Appliance if you are using a virtual appliance.
Procedure
What to do next
You can now import the new certificate. See Refresh the Security Token Service Certificate.