twest Thanks for the reply.
the DNS entry was in place for www and non.
my issue appeared to be a propogation thing. i checked and it appeared to have propogated everywhere. however the local server if i pinged saw the old ip.
it somehow managed to issue a non www cert the first time round. then it failed for a few hrs. after dns had some time it then worked well and issued the cert as expected.