Running into a weird bug with BYOC Edge SSL Certs

So I’m seeing a very odd bug with BYOC Edge SSL Certs. We are migrating from Zendesk to Genesys Cloud and using AWS as our BYOC provider. The Edge deployment succeeds, but TLS termination fails with SSL_ERROR_BAD_CERT_DOMAIN.

Background

Zendesk handled certs automatically. In GC, we uploaded a wildcard cert to AWS ACM and referenced the ARN.

Issue

Architect flows route to the Edge, but browsers reject the connection.

Troubleshooting

Verified the ARN is correct. The cert is valid in AWS. Is there a specific DNS CNAME requirement for BYOC Edges that differs from standard GC?