-checkhost already checks the SAN. It is implementation dependent as to whether the CN is checked for.
when certs change, we have to call into nginx anyway. since they go hand in hand, just merge those files. modern reverse proxies do this job integrated already.