Your TLS config is good for now, unless another padding oracle attack comes along and makes those CBC ciphers weak again, or some other vuln.
(your cert is expiring next month btw, might be a good opportunity to set up LetsEncrypt)
When I set the crypto policy in Fedora to Legacy, which lifts those restrictions, I can visit your website.
Chrome doesn't have this problem in Fedora because it ships with its own SSL/TLS specific things bundled (or something along the lines, didn't care to get deeper in the topic).
Edit to add: It’s possible to run update-crypto-policies --set=DEFAULT:SHA1 and avoid enabling the whole LEGACY policy
https://ssl-config.mozilla.org
I tend to use it for generating config's for static Nginx sites, though it can do much more. :)