How to disable TLS 1.0 and 1.1 and maintain certbot updates

Let's encrypt gave me an apache config that has TLS 1.0 and 1.1 enable. I want to disable this but still maintain the automatic certbot updates. How can this be done?

I understand I cannot change the file and specify the protocols here without breaking the updates /etc/letsencrypt/options-ssl-apache.conf

When I try to globally update /etc/apache2/mods-available/ssl.conf it does not work.

There is an older thread here, I have tried all of the suggestions but none of them worked.

certbot 0.31.0 on Raspberry Pi OS

