NSX-T 3.0 added Certificate Revocation List (CRL) checking when applying a certificate to a Manager node/cluster.
If the CRL check cannot be performed, the certificate cannot be applied to a Manager node or cluster.
In the case of LDAP CRL verification, the check may fail if there is a communication issue between NSX-T Manager and the LDAP server.
Although CA-signed certificates that have LDAP CDPs for the Manager may work, they are not officially supported and VMware recommends the use of HTTP CDP based certificates.