From a user point of view ...
Letsencrypt or another certificate authority ... it should not matter...
Just having one set of files ( cer/key/ca-chain) with a clear name referenced from
"all config files" would be the easiest...
Once you get the certs from you provider, you just overwrite the files with your own ,
restart the services and "that's it" ;-)
Letsencrypt renewing does not have to be handled on ovirt host (on a bastion host where
LE is configured, a simple script can be run to update the certs and restart the
services...)
My 0.02€
Etienne