Two seconds more of digging, was all it took. In case anyone else has the same issue after upgrade, you’ll need to remove the inactive account from
/home/user-data/ssl/lets_encrypt/accounts/acme-v02.api.letsencrypt.org/directory
In my case, I had two directories there, 17fbXXXXXXXXXXXXXX and 58a9XXXXXXXXXXXXXX. I deleted the older one and then re-ran “Provision Certificate” from the TLS (SSL) Certificates page.