Ensure that Cloud Director can connect to the URL provided for the OVF import by ensuring that the remote endpoint provides a signed certificate or by importing the remote endpoint's certificate to Cloud Director's Trusted Certificates manually.
Manual Import
Notes:
Make sure to test the connectivity between vCloud Director and vCenter and ALL the hosts inside the cluster where the OVF is being deployed
If the connection is successful without any pop-up window showing a certificate, it means vCloud Director already trusts the endpoint
If a pop-up shows up asking to trust and add that cert into the library means that endpoint is not yet trusted
If your ESXi are using VMCA certs you may need to renew them for vCloud Director to trust them as the CA issuing the certificates will become your own vCenter following these steps
Automatic Import
An automated way of retrieving certificates and trusting them automatically can be done this way:
/opt/vmware/vcloud-director/bin/cell-management-tool trust-infra-certs --vsphere --unattended