Yeah, it isn't a good look for flathub. I looked at the certificate and the Subject Alternative Names section was missing the www prefix. Why they're not using Let's Encrypt and certbot beats me because this could all be automated.
I use the DNS-01 challenge to take advantage of wildcard certs. Every 30 days, I have a cron job force a renewal, send a SIGHUP to nginx and I am back in biz. Ez-pezy