We cannot compare unsecured trunks in this case, those will work because you already meet their requirements. The requirement for TLS turnks is to have a valid PEM certificate (
non-wildcard!) issued by the SIP provider so the PBX can talk to them using this certificate. You also have to insert a registrar that supports TLS (ie. don't try to authenticate on their non secured registrar - they have to give you the correct one). Their SRV records must also be able to resolve to a TLS based registrar and the port you use will also be different (ie. providers may use 5060 for UDP, and 5061 for TLS).
I think it is best you contact them to help you, as you probably have the wong configuration in the trunk now and they are rejecting you with a 503. Please confirm the above and let us know accordingly to see what can be done
You can search the forum also for "secure trunk". This post can also shed some light on common cert errors:
https://www.3cx.com/community/threads/secure-sip-on-trunk-503-certificate-validation-failure.70611/