"A general system error occurred: Failed to verify certificate on <IP/Hostname>. When ESXi Certificate Mode is set to custom it is mandatory to install valid certificate on ESXi host before adding the host to VC"
The custom certificate imported to the ESXi host is signed by a Certificate Authority (CA) that is not trusted by the vCenter Server. When the CA root or intermediate certificates are missing from the TRUSTED_ROOT store, vCenter reverts the host configuration to the default VMCA-signed certificate to maintain connectivity.
To resolve this issue, ensure the root and intermediate certificates used to sign the ESXi host's custom certificate are present in the TRUSTED_ROOT store by following these steps:
Export the root and intermediate certificates that sign the ESXi host's custom certificate.
Add the exported certificates to the TRUSTED_ROOT store on the vCenter Server.
Log in to the vSphere Client.
Navigate to the vCenter Server and select the Configure tab.
In the left pane, click Advanced Settings.
Click Edit Settings at the top right corner, filter the list by vpxd.certmgmt.mode, change the value to custom, and click Save.
Place the host where the certificate needs to be replaced in Maintenance Mode.
Navigate to the ESXi host.
Select the Certificates tab for the host.
Click Import and Replace Certificate and complete the import process.
Note: