Most guides out there reference SSL cert changes for vCenter, and not ESXi itself. Since you're filling out the form with the req command, it doesn't really matter where you run it, since you ultimately end up with the cert and the key in the end, which you can move around to where you need them.
So, I just need to create the csr on the vcenter server and then push out that single cert to each host. Correct?
Follow the same directions to generate the new rui.crt and rui.key files and distribtue them to your hosts. You will probably also have to restart the host agents, and reconnect the servers to vCenter.