Fatal alert: bad_certificate

It's possible that it's another node, but it's making HTTP calls not transport protocol calls, so this is not standard cross-node traffic.
It's some sort of HTTP client - possibly monitoring, possibly watcher, or possibly something outside of Elasticsearch that happens to run on that same machine.