You just needed to update ca-certificates package. Before that just disable all repos with https that are failing.
That’s why solution with commenting mirrorlist or using http instead https would work also.
For example if you need to disable only epel repo:
yum –disablerepo=epel -y update ca-certificates
This will also help wget, curl, and anything else that uses SSL certificates.
I solved this issue editing both /etc/yum.repos.d/epel.repo and /etc/yum.repos.d/epel-testing.repo files, commenting all entries starting with mirrorlist=… and uncommenting all the entries starting with baseurl=….