Let's encrypt certificate is cross signed with IdenTrust, which is widely known, but if you've got an old platform it can fail for other reasons like missing support for SHA2.
Which is going to be interesting if a few years from now they do anything wrong and get booted by major OS/browsers. Their certificates are <3 months so it would leave a lot of people scrambling for a solution. It is critical that other CA also adopt ACME to not make Let’s encrypt another too big to fail CA.