Preferred chain Lets Encrypt

Hello,

As you may know recently the Lets Encrypt Root certificate expired. This is causing a ton off issues for us.
We were able to resolve most of them by using the Preferred-Chain option “ISRG X1 Root” that apps like certbot/acme.sh offer. However I don’t see a way to do this with Mattermost that has its own internal scripts to request SSL certs.

Is there any way to do this or are we better off adding nginx as a proxy so we can use acme.sh to get the cert and not handle it through Mattermost itself anymore?

Cheers,
Niels