I got this going in the end:
The issue was that pgbackrest did not like the cert being presented by the S3 server
the fix is:
global:
repo1-retention-full: '14'
repo1-retention-full-type: time
repo1-path: "/pgbackrest/hippo15s3prim/repo1"
repo1-s3-verify-ssl: 'n'
Either that or import the CA certs and reference them in Global.
TLS slows things down significantly so I'm happy enough to have this as our setup is all internal.
Backups working now
G.