Hello,
I have the same problem. I added the ca certificates staging letsencrypt-stg-root-x{1,2}.pem to the os trust list and succeed for the system-agent-install.sh execution however pod cattle-cluster-agent fails with "x509: certificate signed by unknown authority".
I think the problem is that "/v3/settings/cacerts" is empty but I found no way to workaround the problem.