Ok after long last I figured out something that worked. The problem still makes no sense to me, but the solution was to explicitly import the certificate into its accepted list in a very specific way:
Open an https page with the certificate
Click the lock icon and under Connection choose Certificate Information
Go to the Details tab > Copy to File. Choose PKCS #7, single certificate as the file format and save it somewhere (name doesn't matter).
Open up Chrome Settings > Show advanced settings > HTTPS/SSL > Manage Certificates.
Go to the Trusted Certificate Root Authorities tab
Import the certificate you "copied to file" in step 3
Restart Chrome (one of those few cases where you need to)