Thanks for that - it reports "Verification failed: unable to get local issuer certificate". The web browser is perfectly capable of validating the certificate though, so is this doing something differently?
cmcli -T common-ca -sv <your-servers-dns-name-or-ip>:<port>