Ensure to do the following before importing custom identity certificates on the Experience Portal servers:
Remove the EP Signing Certificate
Upload the external CA Certificates as Platform type Trusted Certificate