Looks like the public cert is issued by Let's Encrypt, is valid and the server seems to be properly presenting the full certificate chain, so my guess is whatever machine he's on doesn't have the root CA cert "ISRG Root X1" installed properly in the local trusted root store... maybe a Linux box that needs to update ca-certificates or something...