administrator@vsphere.local) continue to work.The solution is to re-add the Identity Source configuration in vCenter with the new certificate. This requires you to log in using a local SSO administrator account (like administrator@vsphere.local).
Warning: Before removing the identity source, take screenshots of all its settings (Primary server URL, Base DN for users, Base DN for groups, etc.). You will also need to re-add your AD groups to vCenter roles (under "Global Permissions" or other objects) after re-adding the source.
administrator@vsphere.localMenu > Administration > Single Sign On > Configuration > Identity Sources.Remove.Add to create a new identity source. Active Directory over LDAP.Save to apply the changesKB 383112: AD Authentication Failure in vCenter Due to LDAPS Certificate Mismatch
KB 316596: Configuring a vCenter Single Sign-On Identity Source using LDAP with SSL (LDAPS)
Reference : Add or Edit a vCenter Single Sign-On Identity Source