Certbot picks up wrong CN from the SAN list while renewing/creating cert

This doesn't appear to be an option in certbot, but I think you can do it if you provide your own CSR:

It can be done in some other ACME clients.

3 Likes