VMware Cloud Foundation 9.1
An architectural design change in VCF 9.1 migrates certificate orchestration from SDDC Manager (SDDC-M) to a decentralized Fleet Lifecycle service. OpenSSL CA configurations established in VCF 9.0.2 through SDDC-M do not migrate to the new design. The system subsequently treats legacy certificates as external entities.
Reconfigure the OpenSSL CA at the fleet level to restore managed status and re-enable auto-renewal. This procedure is a one-time operation.
The Certificate Type displays as OPENSSL CA once the steps are complete, and lifecycle automation restores.
Refer to the below document for detailed steps:
Configure a Certificate Authority for VMware Cloud Foundation