I generated it with
certbot renew --force-renewal --preferred-chain "ISRG Root X1" as I thought was how to do it?
In the nginx conf
ssl_certificate /etc/letsencrypt/live/sentry.wikblad.com/fullchain.pem; # managed by Certbot #
ssl_certificate_key /etc/letsencrypt/live/sentry.wikblad.com/privkey.pem; # managed by Certbot