So Windows XP...
There are a lot of old systems out there running API's, automation, industrial systems, etc. They never get updates, and are expected to last decades. Most of them aren't on the public internet, but HTTPS would still be a good idea. This change is going to mean a bunch of them just get changed over to having no encryption.
Though I imagine that's extremely expensive. I expect that has something to do with this decision - they are a non-profit after all.
This is going to cause a lot of stuff to break, and it's 100% LE's responsibility.
HN's root cert is valid through 2038.
LE could have gotten cross-signed by a cert that didn't expire so soon, but they didn't.
And they still could.
Expecting XP or say Windows 98 to still work on modern day standards is just laughable.
Upgrade, or get left behind. The concept of 'never updating' isn't one that is practical and you'll pay the penalty for it later on.
I also know that we get a number of students connecting with Android v3 or earlier from these same locales.
I found Linux Lite, based on Ubuntu 18.04 LTS:
Or, for industrial use a hundred bucks on a certificate from an older CA is nothing.
Just tested with the new LE root cert and it doesn't work.
LE says "it's CA problem, not a Let's Encrypt problem", but that's disingenuous.
Let's Encrypt chose to get cross-signed by a root that expires in a couple years.
For example, HN's root doesn't expire until 2038.
This is definitely a Let's Encrypt fuckup that will cause many sites and apps to break.
If its that important to you or if its a commercial offering in an 'industrial setting', you should have no problems acquiring a cheap SSL certificate from another source. You can literally get them as low as $6 a year right now.
LE provides a great service and continues to do so. If you want to nitpick, then jump to a 'competitor'.
Sure, I can solve the problem by switching to a different CA, or by adding the ISRG root cert to each device.
But this is a problem that didn't need to happen. I blame myself for not anticipating it when I selected LE.
And I blame LE for cross-signing with a root cert that expires so soon. Not a good choice for a new CA that will take many years to be trusted on most devices.