Which keys to use in Load balancer, when server handling multiple domains?

You’ll need a single cert with all the (sub)domains instead.
Having one server redirect/proxy /.well-known/acme-challenge/ to the other may make completing the http-01 challenge easier if you’re using that one.