AWS now provides certificates for AWS resources through ACM. Certificates issued to AWS API Gateway and CloudFront appear to be signed by "Starfield Class 2 Certification Authority". This results in SL_ERROR_BSD_ESECUNKNOWNROOTCA when connecting to our servers.
https://aws.amazon.com/certificate-manager/faqs/
Also, can we get a list of the actual fingerprints for the trusted catalog CAs? A lot of the names in certificate chains are similar and leads to confusion.