There is something wrong with the trusted ciphers. FC24-25 defaults to FUTURE set of ciphers in /etc/crypto-policies/config. Changing that to default and running update-crypto-policies fixed this for me. Something is probably off in the FUTURE backends/gnutls.config.

With FUTURE even wget gets an error on the cert:

wget -p -O /dev/null ""
WARNING: combining -O with -r or -p will mean that all downloaded content
will be placed in the single file you specified.

--2016-11-28 13:51:25--
Resolving (,,, ...
Connecting to (||:443... connected.
ERROR: The certificate of ‘’ is not trusted.
ERROR: The certificate of ‘’ was signed using an insecure algorithm.