Currently using custom CA cert for SDDC manager component and want to replace the cert with self-signed (OpenSSL) certificate.
VCF 5.2.2
Prepare a Backup
Take a snapshot of the SDDC Manager VM before proceeding.
Generate a CSR
In the SDDC Manager UI, navigate to Inventory > Workload Domains > Management Domain.
Select the Certificates tab.
Select the checkbox for the SDDC Manager resource type and click Generate CSRs.
Complete the wizard with the required organizational details and generate the request.
Generate and Install Self-Signed Certificate
In the same Certificates tab, select the SDDC Manager resource again.
Click Generate Signed Certificates.
Select OpenSSL from the Certificate Authority drop-down menu.
Click Generate Certificates.
Once generated, select the resource again and click Install Certificates.
Verify Access
After the task completes, refresh your browser (or clear the cache) to access the UI using the new self-signed certificate.
For detailed steps on handling UI inaccessibility during this process, refer to KB Sddc manager machine SSL certificate expire, UI not accessible. If you need to perform this for other components like vCenter, see Renewing self signed certificates of vCenter via SDDC manager with Open SSL integration.