It seems I cannot post a full explanation of context so here is the short version. Ill add detail after.
Devices in field all suddenly unable to connect to GCP host.
Problem simplified to https_client sample with url changed to run.app and certificate changed to WR2.
Modem trace shows handshake terminating with TLSv1.2 Record Layer: Alert (Level: Fatal, Description: Unknown CA)
Given that I can connect with the same certificate and cipher using curl. Is this a bug? How should I proceed?