This was sufficient to get the firmware to download the .EFI file successfully. Perhaps the autoexec.ipxe file isn't using the same cert (or isn't supporting TLS at all)? Changing the URL to http: ...