When the cert was renewed, did the cert chain change? When hitting https://api.twitch.tv/kraken/base I see the following chain. All certs are v3
Root - CN = DigiCert Global Root CA, SN 08:3B:E0:56:90:42:46:B1:A1:75:6A:C9:59:91:C7:4A
Intermediate - CN = DigiCert SHA2 Secure Server CA, SN 08:3B:E0:56:90:42:46:B1:A1:75:6A:C9:59:91:C7:4A
Leaf - CN = *.twitch.tv, SN 04:07:57:C9:65:FD:09:8F:2D:C4:0C:66:72:C9:F6:0B
I’m unsure the root and intermediate are installed by default. For hosts in private space firewalled from the internet you may need to install the root/intermediate manually, or publish them via GPO.