I have exactly the same error, although the certificates are not revoked and are trusted on the client. I have also tried legacy and instances, but unfortunately without success. This applies to the Road-Warrior setup. My S2S connection runs without any problems.
Have you been able to find out anything yet?
Have you been able to find out anything yet?