Okay, so HostPapa finally responded. They said that cPanel makes the API calls and issues the certificates like this due to recently introduced Let’s Encrypt rate limits of 300 certificate orders every three hours. They say cPanel has to adjust for issuing individual certificates on a big server and that this would happen on any hosting company that uses cPanel at the moment.
Is that really true, that any hosting company using cPanel where a customer has a handful of domains and several subdomains that the certificates would be merged into a few (randomly selected bunchings of) certificates??
And if it is, would I in theory be able to tell them to at a minimum configure it so it uses wildcards and combines the certificates in a particular way that prioritizes unique certificate by domain? Because the current way it does it is a subdomain is more likely to have its own certificate but all the main domains are merged into one.
Edit: By the way is the 300 certificates/3 hour thing new? I find references over 2 years old to it on these forums, and HostPapa only migrated my server in February of this year which is when the problems started. I also read on these forums here 300 New Orders per account per 3 hours - Renewals that if a provider is large and needs more than that they can override it, so is that a valid excuse even in the event that the merger of certificates is caused entirely by cPanel wanting to stay under the limit.