Okay, the required command was not mentioned where I expected it (but I do kow somewhere else on TMO ). So we go here: you need to fetch the certificate in PEM format from issuer and execute Code: ~# cmcli -c common-ca -a downloaded.certificate.pem cmcli --help tells you more ... -- of course it is a cert chain and the other certs are also newer you need to install them too.
~# cmcli -c common-ca -a downloaded.certificate.pem