Did some more digging, and found this from 2018.
https://github.com/vatesfr/xen-orchestra/issues/2723
Curious if that is still relevant almost 7 years later
If it is, then I wonder if there is another way to allow the connections other than xe host-emergency-disable-tls-verification
Not going to try that yet though.
jcharaoui created this issue in vatesfr/xen-orchestra
closed
SSL certificate verification fails in stats query
#2723