I see cert-manager does support dns-challenges (route53). So I can use it and replace the tls-rancher-ingress secret directly. The question now is how I tell rancher to reload the ingress. Maybe it does it automatically anyway. It should, actually, if it behaves like a normal nginx ingress.
And I also have to figure out how I can do a dry-run with cert-manager.