Wildcard is not used here because we have external DNS. It's already disabled by "allow-wildcard-certificates = false," but it has nothing to do with the problem here.
Related to Apache, as explained above, Let's Encrypt cannot verify via http, which is why an error message appears.
Conclusion: If the mail.domain.tld checkbox is selected, it's not possible to create a certificate.
See screenshot in the attachment.
@Gjimi
It is an incorrect conclusion.
I have tested your alleged "bug" and your error notification cannot be reproduced.
This is expected, since the LE certificate created will be assigned to / used for the mail.domain.tld too.
The error notification that you receive is related to a - totally - different issue.
In your case, the cause of the problem seems to be some incorrect configuration with respect to IPv6 settings
and/or DNS settings.
In fact, first check whether IPv6 is allowed
and working properly on the server side.
Could you be so kind as to simply remove the AAAA record (if possible) or to replace it with a A record?
After that step, please retry certificate renewal.
If you still have some issues, please report them.
It is not necessarily related to DNS alone, it can also be related to IPv4/IPv6 config issues on the server.
If the replacement / removal of the AAAA record works, could you be so kind as to (only) allow IPv4 on the server, with
afterwards certificate renewal?
If that works, could you also be so kind as to reinstate the IPv6 properly and try to renew the certificate (with IPv4 only settings).
If the latter also works, then please try to reinstate the AAAA record and ...... surprise, surprise ...... try to renew the certificate afterwards.
If the final step does not succeed, then is very likely - but not 100% certain - that you can report a bug concerning the SslIt! extension.
As a final remark, there are some other remarkable issues with SslIt!, so please do some careful testing in order to make sure that the potential bugs and solutions can be identified.
Kind regards....