You can use the Platform Services Controller to set up your environment to use custom certificates.
You can generate Certificate Signing Requests (CSRs) for each machine and for each solution user using the Certificate Manager utility. You can also generate CSRs for each machine, and replace certificates when you receive them from the third-party CA, using the vSphere Client. When you submit the CSRs to your internal or third-party CA, the CA returns signed certificates and the root certificate. You can upload both the root certificate and the signed certificates from the Platform Services Controller UI.