Thank god I found this thread. On renewal yesterday I got this issue also, and specifically it broke docker mailserver which automatically gets the new certs upon renew. I ended up on YR1, and got it sorted like this:
Most TLS servers don't need or use the ISRG Root X1 in their chain. TLS Clients use the cert chain sent by the server to match to that trusted root that already exists on their system. That's how they know it is trusted.
But, if yours does how is what you did any different than what you did before? The X1 root has not changed. Nor was it ever in the intermediate from Let's Encrypt that is getting "truncated" in the pfSense /conf/acme directory.