Browser access to the server uses secure access. The browser used therefore needs to have a copy of the same CA certificate as used to sign the virtualized server's own identity certificate.
If the server is using its own auto-generated certificate, you can downloaded the certificate from the Certificates section of the menu. Download the DER-encoded certificate (a CRT file).
If the server is using an identity certificate generated elsewhere and then uploaded to the server, obtain a copy of the CA certificate from the same source.