Buy certificate without Port 80/443

Hello!
I got Nextcloud up an running for about 6 month now and I now want to buy a longlife SSL certificate.

I got one fixed IP address, Port 80/443 is used by Exchange so I set Nexcloud on a different port.

How do I get a certificate for the Nextcloud Server? Can I set up a common certificate for Exchange and Nextcloud, subdomains are i.e. exchange.domain.com and cloud.domain.com? Or even with 3 subdomains as we are thinking of a Jitsi Server as well.

Thanks for any hints.

Martin

You can use for every name the port 443. Perhaps because of proprietary exchange it does not work with virtual host. Perhaps you need then a reverse proxy. Use Lets Encrypt for free.