I changed it so it generated a cert with multiple SANs rather than a wildcard.. the nice thing is I can specify the web root in the command and it'll put in a challenge file that it'll read, so doesn't require creating challenge TXT records in the DNS which was super annoying.
Uncertainty is an uncomfortable position.
But certainty is an absurd one.