Everybody installs the certificate on the server. The handshake fails everywhere else.
TLS trust in an Extended ECM landscape is not one setting. OpenJDK, Content Server's own bundled JRE, SAP STRUST and the Windows certificate store each keep a separate list, and a handshake error is always fixed in the component that made the call.