Let’s Encrypt cuts certificate lifetimes to 64 days starting February 2027

AI-rewritten: This is a summary of an article from Ars Technica, rewritten by AI (Qwen, running locally) to make it easier to read. The facts come from the original article – read it for the full story.

Ars Technica •
Nick Indge
• October 8, 2026

Let’s Encrypt is reducing the lifetime of free SSL/TLS certificates from 90 days to 64 days, starting on February 10, 2027. The organization plans to begin testing these shorter certificates on October 14, allowing interested users to opt in before the change goes live for everyone. This adjustment aims to push more users toward full ACME automation rather than relying on hardcoded renewal schedules or manual processes that may cause unexpected expirations.

Before this launch in early 2016, certificates were often issued for one to three years. Let’s Encrypt initially adopted 90-day certificates to force renewal automation and limit vulnerabilities from private key thefts. While the industry was shocked by the initial move, shorter lifespans reduced potential damage if a certificate was compromised or assigned in error. The organization has already announced that default lifespans will shorten further to 45 days in 2028.

To support this transition, Let’s Encrypt is also compressing validation timelines. Authorization reuse periods will shrink from 30 days to 10 days, eventually reaching seven hours by 2028. This step should eliminate the need for CAA rechecks, though most operators will not notice unless their ACME clients depend on cached validation data. Administrators have approximately four months to test their renewal automations before the February 10 deadline to avoid downtime.

Source: Ars Technica •
Nick Indge
• October 8, 2026

Read the original article at Ars Technica →

Leave Comment

Your email address will not be published. Required fields are marked *