The certificate of JOSM's site was for a long time self-signed because of a lack of free certificates from certification authorities for open source projects. Since January 2014, we use a free certificate provided by GlobalSign through its Open Source initiative.
In case you want to be absolutely certain that the certificate you fetched is really the legit one, verify that the certificate's SHA1 fingerprint is AB:EA:94:03:21:C2:0F:DE:B2:79:C2:52:63:12:D5:52:F7:BA:43:C9. It very likely is.
The certificate is also available for download.