on package upgrade, /lib/systemd/system/certcentral.service gets overwritten with the one shipped in the debian package, this effectively makes certcentral unable to reach the ACME directory servers till puppet runs again and deploys the proper service unit file.
We have two options here:
- get rid of the service file in the debian package as is managed by puppet
- don't overwrite it on upgrades