In theory, perhaps. But it really depends on how requests reach the two servers. Is there a single IP with load balancing? Are there multiple IPs with the same DNS name?
Both sound tricky to make sure the challenges make it to the server that sent the HTTP-01 request unless they somehow share the
.well-known folder. That way they both serve from that shared folder and write to that shared folder.
Expiration emails won’t work reliably unless you request two technically different certificates. For example, #1
domain.com. Let’s Encrypt will see them as two different certificate timers, so you’ll get warning emails if either one fails renewal for long.
Or maybe DNS-01 challenges would provide you with different solutions?