I believe this is a bug caused by the code responsible for checking that a domain ends in a public suffix expecting the domain to be encoded in unicode, while it’s currently being provided as punycode.
I’ve filed an issue here as well as a potential fix, but it’ll probably take at least until Thursday or Friday for this to be deployed (assuming the fix is adequate and will be reviewed and merged in time). (This is a guesstimate based on the typical release schedule, nothing more. )
Update on this: We have a plan to fix this in Boulder, and are getting some help from the maintainer of an upstream component. It will take a few weeks to fix. Thanks for reporting!
Sorry for commenting in a closed thread, but I just wanted to point out that this fix was deployed successfully today and people are now able to get certificates for these IDNs. Thanks to everyone who made that happen!