Vulnerability analysis tools generate alerts containing the following signature when assessing vSphere infrastructure components:
"The following certificate was at the top of the certificate chain sent by the remote host, but it is signed by an unknown certificate authority"
VMware vSphere ESXI 7.0.x
VMware vSphere ESXI 8.0.x
The Certificate Authority (CA) responsible for signing the ESXi host certificates is not recognized or trusted by vulnerability scanners (e.g., Nessus, Qualys).
Remediation of this reporting anomaly can be executed via three standard administrative approaches:
If the deployment relies on valid, default VMCA certificates, the IP addresses or Fully Qualified Domain Names (FQDNs) of the affected ESXI hosts can be whitelisted or added to an explicit exception list within the vulnerability management console.
Reference KB : Step by Step Process to replace ESXI vmca certificates to Custom from vCenter UI
https://<vCenter_FQDN>..0, .crt, or .pem extensions).