The scripts at $DAYJOB have been using the unqualified domain-name instead of the FQDN just fine for years.
So if the outsourced netadmin team mistakenly removes the unqualified domain-name from a TLS cert (replacing it with garbage), those scripts will all suddenly fail catastrophically because they rightfully refuse to trust the connection.
Sigh. π