The CAA record is queried by the CA before the certificate is issued. It's mandatory for the CA to query for the CAA record, but not for the CAA record to exist in the first place. The fact that a valid certificate has been issued, would indicate that this isn't the problem. TLS appears to be configured and working fine. The site requires a number of resources and specifies those resources using the http scheme, fixing this should be a case of updating a few urls.