Basically, the in-line spam filter, a number of Django applications on Apache and a (never finished) Shibboleth SSO service, all on Linux. Once set up, a cron job took car of the renewals. We did not run into any complaints that the LE certs triggered security warnings.

Do use the test certs until all kinks are worked out on the pilot setup. It does take a few tries to get a grasp on the clients and the variety of ways it can install /renew certs.

There is no official MS client because the Windows cert store does not play nice with the model used to install/update the certs.