If you set up your ESXi hosts to use custom certificates, you must update the TRUSTED_ROOTS store on the vCenter Server system that manages the hosts.
Prerequisites
Replace the certificates on each host with custom certificates.
Note: This step is not required if the
vCenter Server system is also running with custom certificates issued by the same CA as those installed on the
ESXi hosts.
Procedure
What to do next
Set certificate mode to Custom. If the certificate mode is VMCA, the default, and you perform a certificate refresh, your custom certificates are replaced with VMCA-signed certificates. See Change the Certificate Mode.