API returns error "urn:ietf:params:acme:error:malformed"

sub.domain1.com would be covered by the *.domain1.com wildcard...unless of course you need *.sub.domain1.com which is different and should be ok to include with the existing order.