Solved for me :
If Enrollment Server is installed on SubCA Server : do this :
On the enrollment server, add the following reg keys:
[HKEY_LOCAL_MACHINE\SOFTWARE\VMware, Inc.\VMware VDM\Enrollment Service]
"UseNTLMAuthenticationToCa"="TRUE"
"UseKerberosAuthenticationToCa"="FALSE"