FWIW this was entirely down to a problem in the GCDS tool (or my use of it).
Although GCDS bundles it's own JRE and keystore, it had defaulted to using
the system JRE and keystore.
to config-manager.vmoptions (in the GCDS base directory) got it working
(after adding the ca cert).

I imagine using the GCDS documented method of adding a CA (but referencing
the system keystore) would have a similar result.
