Simon, looks like you catch situation described in this post. There is no problem with configuration, looks like it's nginx behavior. As well, there could be problems with Let's Encrypt OCSP.