Try to hit likely DNS names, or at least provide a means of manipulating /etc/hosts to induce a good domain for the default certificate SAN fields. Note putting the FQDN first in /etc/hosts will get the FQDN in the certificate.