Let‘s Encrypt describing their ACME profiles in detail:
‚classic‘: 90 days, all as before
‚tlsserver‘: 90 days, smaller certs, cut lean for its server role and modern clients
‚shortlived‘: ~6 days, otherwise like ‚tlsserver‘
If you have no idea what the mentioned TLS extensions are about, do *not* configure a profile. But if you do, use classic.
If you have a rough idea and serve modern clients, tlsserver cuts some bytes and the auth process is tighter.