SYSTEM Cited by 2 sources
Let's Encrypt¶
Let's Encrypt is a nonprofit public certificate authority (CA) run by the Internet Security Research Group (ISRG). It issues free, short-lived, domain-validated SSL/TLS certificates via an automated protocol (ACME) and is one of the most widely trusted public CAs in the world — "a nonprofit CA run by the Internet Security Research Group (ISRG), which has issued certificates for more than 300 million websites to date" (Source: ).
Role in managed-service TLS¶
Managed-service vendors that terminate TLS on behalf of customers (databases, APIs, CDNs) routinely use Let's Encrypt as their serving CA because (a) it is pre-trusted by every modern OS and browser, (b) issuance and renewal are fully automated via ACME, and (c) cost is zero. The pre-trust property is load-bearing: clients with a stock public-CA trust store validate the chain without configuration, so the managed service "just works" for the majority of traffic.
The ISRG Root X1 anchor¶
The root certificate is named ISRG Root X1. It is the trust anchor that all Let's Encrypt leaf certificates chain to, and it is the PEM users need to obtain when a peer (a third-party tool, an embedded device, a legacy driver) ships without a stock trust store. Let's Encrypt publishes the PEM at https://letsencrypt.org/certificates/.
Seen in¶
- — PlanetScale's serving certificate is issued by Let's Encrypt. Canonical wiki disclosure. Third-party tools (Google Data Studio / Looker Studio, Retool) that don't ship the public-CA trust store connect to PlanetScale by pasting the ISRG Root X1 PEM into the tool's CA Cert field (the CA-bundled cert for tool trust pattern). The post inlines the full PEM for copy-paste convenience and warns users that if PlanetScale ever changes CA, the uploaded bundle will need to be updated in each tool.
- sources/2026-09-29-cloudflare-building-a-certificate-authority-for-the-whole-internet — Let's Encrypt's scale (10 M certs/day, >500 M sites, 4 B active certs in 2025) is cited as the concentration risk motivating a redundant free public CA — the Cloudflare Certificate Authority. Positioned as "one of the best things to happen to the Internet in twenty years," said explicitly by "one of its largest users."
- sources/2026-09-29-cloudflare-building-a-post-quantum-certificate-authority-with-merkle-tr — Let's Encrypt's Boulder ACME software is named as the well-tested base Cloudflare forks for its MTC CA, and Let's Encrypt is itself actively developing MTC support in Boulder — the upstream Cloudflare tracks and contributes back to.
Concentration risk: the dominant free CA (2026)¶
By 2026 Let's Encrypt is not just a free CA but the operator that carries most of the free-cert web: ~10 million certificates issued per day, >500 million sites served, and >4 billion active certificates as of 2025. Cloudflare — one of Let's Encrypt's largest users — names this exact success as systemic risk: "if the dominant free certificate authority had a bad week, much of the web would have no comparable free, automated alternative ready to take the load." That argument is the motivation for the Cloudflare Certificate Authority — a second free, ACME-first public CA as ecosystem-scale redundancy (the blast-radius framing applied to the free-cert layer). (Source: sources/2026-09-29-cloudflare-building-a-certificate-authority-for-the-whole-internet)
Operational properties¶
- Validity: 90 days (short-lived by design).
- Automation protocol: ACME; clients like Certbot, acme.sh, cloud-provider ACME integrations manage renewal.
- Pre-trust: bundled in modern OS + browser CA trust stores
(macOS/iOS, Windows, Android, major Linux distributions,
Firefox/Chrome/Safari/Edge). Legacy embedded devices and
minimal containers (Alpine without
ca-certificates) may lack trust and require explicit bundle install. - Rate limits: public documentation caps issuance per domain and per-account to prevent abuse; enterprise-scale deployments request higher limits.
Related¶
- root-ca-trust-store
- self-signed-cert-antipattern
- mutual-tls
- systems/certificate-transparency
- systems/cloudflare-universal-ssl
- systems/planetscale
- ca-bundled-cert-for-tool-trust
- systems/cloudflare-certificate-authority — the redundant free public CA Cloudflare is building, motivated by Let's Encrypt's single-operator concentration.
- systems/boulder — Let's Encrypt's ACME server software; Cloudflare forks it for MTC issuance, and Let's Encrypt is adding MTC support to it upstream.
- systems/web-pki — the trust system both CAs operate within.