Android Private DNS doesn't work with `dns.phowork.fr`
Reason: Let's Encrypt default certificate chain crosssigns certificates with (expired) DST Root CA X3, which Android tries incorrectly to validate.
Solution: add --preferred-chain="ISRG Root X1"
flag to lego
command on acme_servers