I've done something similar, but sure if its applicable in this case.
My requirement was to allow the CP Mgr access to the internet via a Fortigate which was doing https inspection. Therefore the only way to achieve this was to ensure the Fortigates certificate was trusted by the Mgr.
We had to add the cert in two places, the reason for this was to firstly ensure the Application level could get updates ie. IPS etc, and secondly so that the OS could get updates, ie. Jumbos etc.
The way I got it working was never confirmed as a supported solution by TAC, but at the same time they never really gave me a solution either.
Is this what you want to do?