> since if they start with a brand new root certificate then I'm not sure what happens with the older browsers.
IdenTrust will cross-sign Let's Encrypt root cert. I imagine they will keep it cross-signed, for backwards compatibility, once LE has their root cert in all the browsers.