R3 certificate renewal

LetsEncrypt signs all Leaf/EndEntity Certificates with an Intermediate (currently R10, R11, E5, E6), which is signed by ISRG Root X1 or X2.

The intermediates are randomly chosen and may be replaced at any time. R10/R11 can be considered replacements for R3. R3 is retired and will no longer sign anything.

The X1 and X2 root Certificates should be in your trust store.

Enrolling any Leaf/EndEntity Certificate (for a domain) into your system will require enrolling the "fullchain", which is the combination of the Leaf/EndEntity certificate AND the chain of intermediates bridging the trust from that certificate to X1/X2.

It's the Trust Store on the SAP platform.