If it helps RMVG to get working then as the Zimbra user simply running
zmtlsctl https
then correcting the resulting saslauthd.conf and saslauthd.conf.in to reflect
zimbra_url:
https://@@zimbra_server_hostname@@/service/soap/
should get it working for now (after a restart!). I checked with another clean install of Zimbra and it works fine if done that way (or of course editing the script instead). May be simpler to go the clean install route incase you changed other stuff on the certs getting here.
I presume the next release will fix the script so its only a short term thing.
Thanks for your help Marcmac.