Not understanding which rate limit is being hit

We found out previously that the limits are set up such that instead of renewals not counting against the domain limit they do count, but are only limited by the separate renewal limit.

So disappointingly it matters which order you do things in, you can issue more up until you hit the per-suffix limit (which it seems you have, that’s what the message says Too many certificates already issued for: spirenteng.com and then you can continue to issue “renewals” (ie issuances of certificates exactly matching a set of FQDNs already issued) but you can’t issue any “new” certificates (ie not “renewals”) even if most of the 20 issued already this week were “renewals”.

I find this a bit frustrating too, but I guess it was easier to make it work that way.