YYYY-MM-DDTHH:MM:SS error envoy[21977] [Originator@6876 sub=connection] Failed to load trusted CA certificates from <inline>YYYY-MM-DDTHH:MM:SS info envoy[22005] [Originator@6876 sub=connection] [Tags: "ConnectionId":"415342"] remote address:<ESXi Host IP Address where the VM is running>:443,TLS_error:|268435581:SSL routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED:TLS_error_end-----BEGIN CERTIFICATE-----<ESXi Host Machine SSL certificate>-----END CERTIFICATE-----When Custom CA certificates are in use, the Envoy service may fail to correctly load or validate the inline trusted CA chain required to proxy the secure WebSocket connection (WSS) from the browser to the ESXi host. Consequently, the connection is terminated by the proxy before it reaches the VM.
This is a known issue in VCF 9.x release and is expected to get fixed in the upcoming releases.
As a workaround, enable the MKS Dev Proxy configuration within vCenter Server Advanced Settings :