The idmap service (hidden under Directory Services) can use a certificate on the system. This will cause an error on cert deletion, and should also be updated if we're updating the system cert. Add this as an option in the script, controlled by a setting in the config file.
See:
https://forums.truenas.com/t/lets-encrypt-with-freenas-11-1-and-later/425/26?u=dan