@Emil I am currently using pfsense and acme plug-in for let's encrypt certificate generation, for you i believe you can try - https://letsencrypt.org/docs/ and see which option suit you the best to do the same.
for some reasons i can't run wireshark from my browser but what i can assure you is that regardless from browser, api tool, and other of my internal services that uses the same have no problem at all.
for now i am happy to leave the validation option off but just feel like it is better to report back here so you guys can have a look at it.