See this Comm Center thread by Sandra Carroll. She uses SSL.com (which by the way we do as well!). They require well-known/pki-validation as a magic cookie path like the ACME one. Add this.
I just validated my own test system cert from SSL.com and it was a snap! Much better than the CNAME thing. Thanks for this suggestion.