The most recent version of Certbot did disable TLS 1.0 and 1.1 in the Apache configuration.
If you can’t upgrade Certbot, I guess you could steal its configuration file. Then there shouldn’t be problems with future upgrades.