thanks, as you mentioned, we need to issue ssl for both domains, the www.exampe.com and the root domain example.com, furthermore, i believe the ssl certs should match the Virtual Host mappings and Domain Aliases
certbot certonly --webroot -w /var/www/html/ -d example.com -d www.example.com