The certificate chain received contained a V3 CA certificate which key usage constraints indicate its key cannot be used to sign certificates

The issue turned out to be the certificate itself, just as the error said! My mistake was assuming the issue was with our systems.

The certificate showed as being correct in the browser but weblogic's authentication libraries appear to be stricter.

The service owner has since issued a correctly signed certificate.

