You can use DNS-01 or TLS-ALPN-01 if you don't want to (or can't) open up port 80.