In the beginning they partnered with an existing CA so that they could issue certificates that where chained to roots already trusted by the major browsers.
“Getting a new root trusted and propagated broadly can take 3-6 years. In order to start issuing widely trusted certificates as soon as possible, we partnered with another CA, IdenTrust, which has a number of existing trusted roots. As part of that partnership, an IdenTrust root ‘vouches for’ the certificates that we issue, thus making our certificates trusted.”
Comments
How did LetsEncrypt get acceptance everywhere?
In the beginning they partnered with an existing CA so that they could issue certificates that where chained to roots already trusted by the major browsers.
“Getting a new root trusted and propagated broadly can take 3-6 years. In order to start issuing widely trusted certificates as soon as possible, we partnered with another CA, IdenTrust, which has a number of existing trusted roots. As part of that partnership, an IdenTrust root ‘vouches for’ the certificates that we issue, thus making our certificates trusted.”
https://letsencrypt.org/2015/10/19/lets-encrypt-is-trusted/
https://letsencrypt.org/2016/08/05/le-root-to-be-trusted-by-...
https://letsencrypt.org/2023/07/10/cross-sign-expiration/
They were Mozilla's child.