> A user wants to get the public key for a certain domain. So he knows he is talking to a server by the domain owner and not some man in the middle.
> So he asks a third party whos public key he already has. In this case Let's Encrypt. Ok.
It works quite differently -- the browser doesn't have to talk to Let's Encrypt at all to verify correctness.
How it works:
1. Browser connects to the server
2. TLS handshake, crypto-stuff
3. The server cryptographically presents the browser his certificate
4. The server's certificate is the server's public key, some attributes (like what domain names the cert is valid for) and a digital signature of all that stuff
5. The browser has a list of certificate authorities
6. The browser checks whether the digital signature on the server's certificate is valid and was made by a CA the browser trusts
7. The browser checks that the certificate is valid for the site it's currently accessing
8. Connection legit
The problem that the CAs (including Let's Encrypt) solve is not distribution of public keys, but rather trusting public keys presented by someone.
> But how did Let's Encrypt get the public key from the domain owner?
> I know they make the domain owner install some software on his server
What the ACME clients do is two-fold:
1. They put up some sort of challenge response mechanism. This is used by Let's Encrypt to test whether a client is authorized to rule over a domain.
2. They generate (or use) a "Certificate Signing Request" (CSR). A CSR is basically a digital "sign here" field. The CSR contains the server's public key, what domains it wants to represent etc.. The CA checks the CSR using the challenge-response mechanism from (1) and then signs it digitally. The result is a certificate, which is sent back to the client and installed by the client. The private key of the certificate never left the server.
> If so, why is the Let's Encrypt software so complicated and not just a 5 line script or something?
Well it doesn't have to be complicated. acme.sh is only five (thousand) lines of shell :)
There are a bunch of ways the challenge-response mechanism can work, and there are also a lot of other options, which add to the complexity, as well as installation routines for certificates, which support a bunch of different servers.
A specific case with "static" challenge-response could conceivably boil down to just a dozen lines of shell or so.