The configuration in the Cisco components contains both NSX and vCenter. As part of this configuration the certificates are fetched from the VMware components or provided manually by the user. The SSL/TLS certificates installed on vCenter Server and NSX require Subject Alternative Name (SAN) attributes and the complete CA trust chain in order to be valid within the connector configuration. If the certificates are not SAN configured or the entire chain is not presented, trust may fail.
The certificates need to be configured in vCenter and NSX to meet the Cisco requirements of having the FQDN of the component within the SAN field of the certificates used by following the below steps, alternatively an external CA certifcate can be generated and imported.
If certificates are replaced with SAN configured ones and issues remain, Cisco support should be engaged to assist and review the cause of the connector trust failure, if advised then VMware support can be engaged.