You need create the CSR for consoleproxy with the correct FQDN of the consoleproxy. And you have to access it by the FQDN. I don't know if it is possible to add subject alternative names to the CSR. If yes, it could be possible to access it by IP and FQDN. Be sure that you import the Root Certificate of your CA into the keystore. The installation guide describes that very well.
http://pubs.vmware.com/vcd-51/topic/com.vmware.ICbase/PDF/vcd_51_install.pdf
Page 16 ff