This issue is resolved in VMware vCenter Server 7.0 Update 3, see Download Broadcom products and software
Workaround:
To workaround this issue, reset the STS Certificate following the KB >> https://knowledge.broadcom.com/external/article/316619
"Signing certificate is not valid" error in VCSA 6.5.x/6.7.x and vCenter Server 7.0.x
For more information on vCLS, see vSphere Cluster Services (vCLS) in vSphere 7.0 Update 1
For more information on STS certificates, see Managing the vCenter Server Security Token Service
Impact/Risks:
This script interacts with the VMDIR's database. Take an offline snapshot concurrently for all vCenter Servers in the SSO domain before running the script. Failing to do so may result in an unrecoverable error and require redeploying vCenter Server.
Once the script is complete, restart services for all vCenters in the site domain. As such, the below script fix will require outages for all vCenters in the site domain.