7.0 U3
This happens because the lookup service is not syncing the updated certificate thumbprints into the database. As a result, the vpxd extension and other vCenter services cannot update their entries and fail to recognize the new certificates.
The issue gets resolved by promoting the database manually by following the KB article 313578 and then performing a certificate reset with option 8, as explained in KB 318767. Later all certificates get replaced, the lookup service syncs the thumbprints, and vCenter services come up without errors.
If you are using a custom certificate, follow these steps: