Gaaah - found it. It turned out I needed to download "Developer ID - G2 (Expiring 09/17/2031 00:00:00 UTC)" from https://www.apple.com/certificateauthority/ and open it in KeyChain. Then my other certificate was deemed valid and then I could sign.
Thank you to @ibamba in this thread for pointing to solution
Topic:
Code Signing
SubTopic:
General
Tags: