There is a module called "mod_md" which gets and renews certificates from LE. It's part of 2.4.43.
...
You do not need to have port 80 open to use it. It also works with port 443 alone.
Stefan, thanks. I've read a bit about mod_md but wasn't sure if I could add a new, certless domain. I'll try it, then.