Use a public key for the main webserver's TLSA record.
[zones] / certs /
drwxr-xr-x   ..
-rw-r--r-- 6340 distorted-ca.cert