Doing it on a JVM server like Jetty is a pain, and the (usually helpful) Jetty devs wont help. In another month or so I'll find out if I've done enough.
Then it's not Let's Encrypt - as per their FAQ:
"Our certificates are valid for 90 days. You can read about why here.There is no way to adjust this, there are no exceptions. We recommend automatically renewing your certificates every 60 days."
However it could be you're using Certbot with another service - since the ISRG aren't idiots, they created a standardised protocol (ACME), and there are several other CAs that use it now.