Ok this is all done
I thought about getting a new cert from letsencrypt so we can get our server on the mumble public list, but until discord actually runs out of venture capital money I don't think mumble's public list is going to get much use, so it feels like a huge effort for very little gain at this moment. So i'll use the self-signed cert mumble generates.
This means when you connect for the first time, you get a popup asking if you really trust me