I have the DST Root CA X3 certificate, so from my basic understanding that should enable a letsencript certificate to work?
If I do add the ISRG Root X1 certificate how do I verify its thumbprint?
And isn’t adding a root certificates myself from the internet a bad idea?
Sorry if this is posted in the wrong section, there does not seem to be a configuring clients forum or documentation section, which further adds to my assumption that this is the wrong thing to do.
So, the site owner is sending the ISRG signed intermediate instead of the one signed by DST Root X3. Ideally they should send the cross-signed intermediate.
In the case that the site owner doesn’t change the intermediate they send, you would need to trust the ISRG root manually.
When you download the certificate from https://letsencrypt.org/certificates/, you could verify it by comparing what you downloaded with public records: