"vSphere SHA-1 validation. Support for certificates with weak signature algorithms has been removed in vSphere 8.0. Weak signature algorithm certificates must be replaced before upgrade."
An ESXi host that was previously removed from SDDC Manager was not properly removed from the vCenter Server inventory. This orphaned host retains a legacy certificate utilizing the deprecated SHA-1 signature algorithm. vSphere 8.0 strictly enforces security standards that prohibit weak signature algorithms. The presence of this non-compliant certificate in the vCenter inventory triggers the validation failure during the SDDC Manager precheck.
Navigate to Inventory > Hosts.
Review the list of active hosts managed by SDDC Manager for the target workload domain.
Log in to the vSphere Client for the target vCenter Server.
Compare the vCenter Server host inventory against the SDDC Manager host inventory.
Identify any ESXi hosts present in the vCenter Server inventory that are missing from the SDDC Manager inventory. These represent the orphaned hosts causing the validation failure.
Manually remove the affected orphaned ESXi host(s) from the vCenter Server inventory.
Rerun the SDDC Manager precheck for the vCenter Server patch. The precheck passes once the non-compliant certificate is removed from the inventory scope.
Note: Check and verify the host is decommissioned and holds no active workloads before removal, e.g. A host must be disconnected or placed in Maintenance Mode before it can be removed from the inventory.