I think when "pulling" updates from server1, server2 has to use its own key and certificate, not the one from server1 (likewise for the CA), and vice versa.