Starting with vSphere 6.0, the new PSC component includes not only the SSO part but also a certification authority, VMware Certificate Authority (VMCA), for certification management of all vSphere infrastructure components. This simplifies not only the certification management (with auto-enrollment for expired certificates) but also the trust between the different connections.
In this environment, the vSphere certificates are generated and issued by the VMCA and stored by the VMware Endpoint Certificate Store (VECS). However, to avoid browser warnings, you need to trust the VMware's CA by adding it in your certification chain. First of all, you need to get the CA root certificate. You can directly download it from ...