the lag time with which LE lets you add arbitrary subdomains to a DNS with wildcard is abominable, like maybe you can add one every half hour or longer, i dunno how short is the window but it was causing me such hassles i'm so sick of it
but now i see this fucking gay SSL shit they forget to mention they need an interFUCKINGmediate cert attached to the cert for LINUX OPENSSL to recognise it