I've switched to wildcard certificates with DNS validation. Everything worked amazing.. 
#nixos saves another day I guess