Hi
I was about to do the same mistake.
But I came across this KB article (https://kb.vmware.com/s/article/79248) and realize it is actually not STS certificate.
Please use the attached script in the KB and run the command.
In my case, it was vsphere-client certificate (solution user) expired. It was for some reason internal CA signed. We simply recreated using VMCA.
Hope it helps someone.
With Great Regards,