ERROR: openssl x509 -hash failed(1): unable to load certificate

Sounds like you may have missed the Build the proper Intermediate CA plus Root CA step.

What’s this show:

openssl crl2pkcs7 -nocrl -certfile ~/ssl/letsencrypt/chain.pem | openssl pkcs7 -noout -print_certs