What version of Java are you building with?
That endpoint looks to be using the relatively-recent Let's Encrypt root that has been migrated to because the old Let's Encrypt root expired at the end of September.
You could also check to see if your java trust store has the "ISRG Root X1" root certificate in it.
```
$ keytool -list -cacerts | grep letsencrypt
Enter keystore password: changeit
letsencryptisrgx1 [jdk], Jun 4, 2015, trustedCertEntry,
```