The goal of this procedure is to replace self-signed External PSC certificates with a Microsoft CA signed certificate.
Helpful blog posts and articles:
http://www.enterprisedaddy.com/2017/01/configure-psc-ha-in-vsphere-6-5-part-1-configuring-certificates/
https://kb.vmware.com/s/article/2112014
https://kb.vmware.com/s/article/2112009
https://kb.vmware.com/s/article/2136693
Environment:
2 External PSC servers (v6.5) behind a load balancer
PSC1 – psc1.myitblog.local
PSC2 – psc2.myitblog.local
VIP – vpsc.myitblog.local