Forcing the client side to have the same certificate trust chain as the server places undue burden to have the two in sync. The clients are many, untrusted and ephemeral, there should be no need to force their upkeep if the check on the VC/ESX can suffice.
I'm not asking about complete bypass of the signature check, which is what -Force does. I still want the check, I just don't want it on the client side.
Hi,
There is such parameter. It's called -Force.