"Certificates issued are marked with the X509v3 Extended Key Usage flags for id-kp-serverAuth and id-kp-clientAuth [...] Other uses permitted by the EKU flags are not officially supported by Let's Encrypt."
"Public CAs typically only allow a small number of EKU flags that are mentioned in the Certification Practice Statement (CPS), in Let's Encrypt's case that's id-kp-serverAuth and id-kp-clientAuth."