Help! SSL borked!

Ok, fixed it by disabling all entries in nginx local.conf bar the root, then repointing the nginx SSL config directly at the renewed letsencrypt certificates - so I could actually start nginx, then running ssl_certificates.py --force. That was nasty. Running ssl_certificates.py seems to be the only easy fix, but if nginx won’t start because the certificates are invalid, ssl_certificates.py won’t run, then you’re a bit screwed.