So we have two websites on the same server (same IP, using SNI), siteA has SSL, siteB doesn't. Google will attempt to crawl https://siteB/ (which will return siteA's content! in a browser you would get a warning about the certificate being wrong). Since there are no links anywhere that point to https://siteB why does google crawl it? This is technically a configuration / apache error, but google should not be crawling https websites when their domain does not match the certificate.
This means that at some point Googlebot discovered https://siteB. It could simply have been a misconfigured CMS, or a bad sitemap, or an errant link one of your visitors shared on a forum, or something a previous owner of the domain did, or anything really. You may think there are no links to the site, and that may be true right now, but it's about something that Googlebot found in the past.
The correct fix is, as you say, to make sure the server doesn't respond to invalid certificate+site combinations.