[email protected]) continue to work.The solution is to re-add the Identity Source configuration in vCenter with the new certificate. This requires you to log in using a local SSO administrator account (like [email protected]).
Warning: Before removing the identity source, take the Snapshot of vCenter depending on Stand alone or linked mode, if it's Linked Mode, power off Snapshot is mandatory. take screenshots of all its settings (Primary server URL, Base DN for users, Base DN for groups, etc.) also need to re-add your AD groups to vCenter roles (under "Global Permissions" or other objects) after re-adding the source.
openssl s_client -connect <DC_FQDN_OR_IP>:636 -showcertsMenu > Administration > Single Sign On > Configuration > Identity Sources.Remove.Add to create a new identity source. Active Directory over LDAP.Save to apply the changes KB 383112: AD Authentication Failure in vCenter Due to LDAPS Certificate Mismatch
KB 316596: Configuring a vCenter Single Sign-On Identity Source using LDAP with SSL (LDAPS)
Reference : Add or Edit a vCenter Single Sign-On Identity Source