Just to update - I found this…
I changed the server_ssl_ca value as suggested (server_ssl_ca: “/etc/pki/katello/certs/katello-server-ca.crt”) on our test server and it fixes the health check.
Is this the correct fix for the live server? Not sure if it’ll break anything else…
Thanks
Rob