Take a look at the list of alternative ACME clients, I doubt they all have a hard dependency on SNI. My money would be on letsencrypt-nosudo. IMO, having to support OpenSSL versions that old would be too big of a trade-off for the official client, considering there are alternatives that do not rely on SNI. But that’s just me.
@kelunik: Distributions often have longer support cycles and backport critical security fixes of software they ship. Not sure if this is the case with CentOS/RHEL and OpenSSL here, but it’s possible.