This article provides information on how to manually reviewing the Certificate Authority (CA) signed SSL certificates in a vSphere 6 or 7 environment. In vSphere 6 and 7, certificates generated by the VMware Certificate Authority (VMCA) can be monitored through the vSphere Web Client. For more information, see the 
View vCenter Certificates with the vSphere Web Client section in the 
Platform Services Controller Administration Guide.
Note: You will need to manage your own certificate validity if you are using your own Private Key Infrastructure (PKI) in your environment.
This article uses the 
vecs-cli command to list certificates stored in the VMware Endpoint Certificate Store (VECS) as well as references the individual keystores used by vSphere. Before proceeding, familiarize yourself by reviewing the 
Where vSphere Uses Certificates and 
vecs-cli Command Reference section of the 
vSphere Authentication Guide.