In vCenter 8.0U2, OpenSSL was updated from 1.1 to 3.1. This new version of OpenSSL 3.1 uses secure defaults that disable the older insecure TLS renegotiation. vCenter 8.0U2 permits only secure renegotiation per RFC 5746. In addition, vCenter's OpenSSL 3.1 uses renegotiation on all outbound LDAPS connections.
Some load balancers deny all renegotiation by default. As a result, they will block vCenter's SSL renegotiation attempts, which terminates the SSL connection and causes authentication to fail.