That will never work, because
pool.sks-keyservers.net only supports unencrypted connections when using the CNAME. Going to an individual server in the pool and trying to use HKPS/HTTPS (e.g.
hkps://pgp.ocf.berkeley.edu) might work on it’s own assuming it has a publicly trusted SSL certificate configured. And unless the OCF keyserver admins had to intervene an manually update it looks like their Lets Encrypt SSL certificate should have been valid 5 days ago when that thread was created as it was minted over a month prior on June 23, 2020.