When using Active Directory over LDAPS, you can upload an SSL certificate for the LDAP traffic. SSL certificates expire after a predefined lifespan. You can view the certificate's expiration date so that you know to replace or renew the certificate before it expires.
vCenter Server alerts you when an active LDAP SSL certificate is close to its expiration date.
You see certificate expiration information only if you use Active Directory over LDAP or an OpenLDAP identity source and specify an ldaps:// URL for the server.
Prerequisites
Enable SSH login to vCenter Server. See Manage vCenter Server from the vCenter Server Shell.