This is likely caused by Followers or Standbys configured with stale or invalid certificates.
When you imported the enterprise CA certificates, did you redeploy the followers? If not, the follower will have the original, self-signed certificate (which has now been replaced with the third party certificate imported into the master).