Problem was:

I generated self signed ca chain with wildcard.

After successfull import, vRA health check started whining about the unkown ca cert:

sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

Then I added the ca cert to java certstore and rebootet ... now it is green again:

vra1:~ # keytool -import -trustcacerts -file /root/ca.crt -alias vra.lab.local -keystore /usr/java/jre-vmware/lib/security/cacerts
Enter keystore password:
Certificate already exists in keystore under alias <load-balancer>
Do you still want to add it? [no]:  yes
Certificate was added to keystore
vra1:~ # keytool -import -trustcacerts -file /root/ca.crt -alias web.lab.local -keystore /usr/java/jre-vmware/lib/security/cacerts
Enter keystore password:
Certificate already exists in keystore under alias <load-balancer>
Do you still want to add it? [no]:  yes
Certificate was added to keystore