You haven't shown the cert (and chain) that your client is using, so, I can't be certain it passes their test:
Acceptable client certificate CA names
/C=US/O=Internet Security Research Group/CN=ISRG Root X1
You haven't shown the cert (and chain) that your client is using, so, I can't be certain it passes their test:
Acceptable client certificate CA names
/C=US/O=Internet Security Research Group/CN=ISRG Root X1