Summary says it all. pkg mirrors are running outdated certs.
The particular mirror I'm connecting to:
"This is pkg0.tuk.FreeBSD.org - a West Coast, USA mirror for FreeBSD downloads."
The script that is supposed to cause nginx to 'upgrade' rather than just 'reload' when the letsencrypt certificate is updated (30 days ago), was not triggering properly.