Let’s Encrypt cuts certificate lifetimes to 64 days starting February 2027

Let’s Encrypt is continuing a push toward improved security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting on February 10, 2027. For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the change should be seamless. For those still relying on hardcoded renewal schedules or manual processes, next winter will be the deadline to update before certificates start expiring unexpectedly.

Starting on October 14, 2026, Let’s Encrypt will begin testing the 64-day certificates, and interested users can opt-in to test their setups before production goes live.

Prior to Let’s Encrypt’s launch in early 2016, certificates were often issued for as long as 1 to 3 years at a time. The service start with 90-day certificates to force renewal automation that didn’t previously exist. Shorter certificate validity periods limited vulnerabilities from private key thefts and accelerated HTTPS adoption across the web.

Read full article

Comments

Scroll to Top