It should compare SANS with the existing cert and see if they've changed, if so add the force flag. This may be better done by getssl itself