So Let's Encrypt's expiration has screwed all 10.11 and lower Macs. Opera and Vivaldi will not run without security cert prohibitions, so the issue may also involve Chromium. Firefox is fine. The thing is, I have IdentTrust 1 on my old Macs but still get the security certificate error when I use Opera. Having the new cert should mean I don't have a problem.
The websites affected are completely random but never big corporate sites like Amazon.com, ebay.com or whatever. Could be a tech blog. So, what is the problem here? What can people with lower than 10.12 do to fix this?
First, this issue is because Apple has refused to support legacy Macs and has tried to make them obsolete by stopping software updates. The DST Root is not the only expired/expiring root, to trigger these changes - many large websites have been switching Trust Anchors to other newer roots that are not available on legacy Macs.
You have two options:
Install the ISRG Root Certificates onto your legacy Mac. They are available at Chain of Trust - Let's Encrypt . You can just download, click, and follow the instructions to add to your system keychain. I suggest downloading the DER version first, that tends to open correctly on Macs.
You need:
ISRG Root X1 - Self-Signed
ISRG Root X2 - Self-Signed
In terms of Opera, it most likely has it's own TrustStore (like firefox) and you have an older version. If you can not upgrade to a newer version because your OS is too old, you will also need to install the Certificates into Opera and any other applications with the same problem.
This same process can be used on other verified roots to add them to your trust store. I've added several on one of my test machines to keep it usable.
Upgrade your Mac to a newer OS. You can find patches for the OSX installers on http://dosdude1.com/, which will bypass the unsupported hardware check, and allow you to install any of the 10.x series on l almost every mac released after 2008.
Half of my team on MacOS/iOS are not able to connect to a number of endpoints with certificates generated including buffalochip.com. There are no failures on Windows and a minority of MacOS/iOS devices can connect.
I have a feeling @Mikek won't be able to load the below sites: