It turned out that I had an incomplete certificate in my Apache configuration. I only had the certificate itself, not also its intermediate.
Ensure target is on latest release (#e10fcbc1), run cpcmd letsencrypt:renew, then wait for panel to restart.