The "Chain validation failed" message means that the certificate doesn't belong to the domain you're trying to open.
To diagnose the issue, connect a device to the WiFi hotspot without MDM, and open the MDM URL in the browser. Make sure the is resolved correctly and the contents of the webpage is relevant.