Workload domain deployment completes successfully, but subsequent integration tasks fail.
This occurs because the deployment natively utilizes self-signed VMCA certificates, which are not automatically trusted by external systems.
Applying a custom customer certificate is required for integration but is restricted to Day 2 operations.
VCF 9.x
Currently in VCF 9.x there is no mechanism or configuration parameter to deploy VCF components (vCenter, SDDC Manager, NSX, VCF Ops) using custom CA certificates on Day 1.
The product is behaving as designed. The customer must complete the deployment using the default certificates, and then follow the official VCF 9.x documentation to replace Replace VMCA Certificate with an External CA-Signed Certificate
Replace a Certificate with an External CA-Signed Certificate