Can not find issuer 'C=US,O=Internet Security Research Group,CN=ISRG Root X1' for certificate 'C=US,O=Let's Encrypt,CN=R3'

Looks like @jcjones may have found the culprit. Unintended switch to serving the short chain by default for renewals.

I'm confused about why that would result in an inability for App Service to find the issuer though since we confirmed the self-signed ISRG Root X1 is trusted and it doesn't expire until 2035. It doesn't bode well for the change currently scheduled for next February that will do this on purpose:

4 Likes