A renewal in dns manual mode writes the previous certificate again. The
second invocation resumes from the domain conf, which carries
Le_LinkOrder and Le_LinkCert from the last successful issuance. newOrder
saves only Le_OrderFinalize, so after finalizing the new order the
`[ -z "$Le_LinkOrder" ]` guard keeps the stale link, the poll reads the
old order, and its certificate URL is the old certificate.
The same gap breaks a first issuance in dns manual mode outright: there
is no stale link to fall back on, and a finalize that answers while the
order is still processing carries no Location header, so the run dies
with "could not get order link location header".
Save the order link where the order is created, next to Le_OrderFinalize,
and drop the certificate link that belongs to the order just replaced.
Fixes#7105