You said you’ve already tried toggling Universal SSL off and back on again, can you post a screenshot of the Edge Certificates page? Hopefully you can see the pending cert and expand it to get more info on what validation type it is using?
If you copy/paste that “Certificate validation request” link, does it load successfully? I’ve had a server that blocks requests to anything that begins with a dot, like .well-known