the tls-sni-01 - challenge is deprecated. Support ends 2019-02-13
So it's better you switch to another validation.
There is your DocumentRoot.
So try (one line)
certbot run -a webroot -i apache -w /var/www/www.squidblacklist.org/
-d squidblacklist.org -d www.squidblacklist.org
You have two ip addresses.
Your configuration
looks ok, your /.well-known/acme-challenge - subdirectory doesn't send nonsense.