Pfsense invalid chains after Y generation cert

Most TLS servers don't need or use the ISRG Root X1 in their chain. TLS Clients use the cert chain sent by the server to match to that trusted root that already exists on their system. That's how they know it is trusted.

But, if yours does how is what you did any different than what you did before? The X1 root has not changed. Nor was it ever in the intermediate from Let's Encrypt that is getting "truncated" in the pfSense /conf/acme directory.