ESX hosts display a warning stating that the certificate status is "expiration imminent." This warning persists even after you successfully renew the host certificates.
The VCSA_ROOT_CERT is approaching its expiration date. Because the VCSA_ROOT_CERT is the root certificate authority used to generate and sign all ESXi host certificates, its impending expiration cascades down the chain of trust. This causes the host certificates to trigger expiration warnings regardless of their individual creation or renewal dates.
Replace the expiring VCSA_ROOT_CERT and subsequently renew the ESXi host certificates. Replacing the root certificate establishes a valid chain of trust with an extended validity period, allowing the newly issued host certificates to clear the expiration warnings.