For anyone else who was following this, I think the issue was because we needed to install the intermediate certificate on the switch, which can only be done via a TFTP upload using the MGMT port. We just decided to disable HTTP(s), but I wanted to add my findings for anyone else who may try to do the same.