My team came up with a "certificate kick" to workaround this.
Open Keychain Access.app
Double-click on the said certificate
Change to Always Trust, close the panel
Open the certificate again
Change it back to Use System Defaults
Close the panel.
This is annoying but these steps works _(ツ)_/¯
At least it's better than rebooting or revoke and get new certificates.
I wish there is a way to script this. (or just fix whatever needs to be fixed somewhere) :).