I looked at updating the cacert.pem bundle we embed which is obtained from here: curl - Extract CA Certs from Mozilla but the update doesn't make any changes to Symantec/Verisign certs and the bundle doesn't need to contain intermediate CA details; in broad terms the signing chain will be followed through live queries until you reach a trusted or revoked certificate; and if neither is reached the process fails.
It's possible this is just another indeterminate LibreSSL problem - we've seen some random/unexplainable issues and it's the reason we switched back to OpenSSL in preparation for LE 8.2/9.0. If you can test a current milhouse Leia build (Generic and Pi hardwar) on a spare USB/SD card that would confirm if that solves the issue.