VYPR
patchPublished Oct 9, 2026· 1 source

Let's Encrypt Halves TLS Certificate Lifetimes to 64 Days in 2027

Let's Encrypt is significantly reducing its default TLS certificate validity period from 90 to 64 days starting February 10, 2027, to bolster web security.

Let's Encrypt, a leading provider of free TLS certificates, has announced a substantial reduction in its default certificate lifetime, shortening it from 90 days to 64 days. This change is scheduled to take effect on February 10, 2027, impacting all newly issued and renewed certificates. Existing certificates will remain valid until their original expiration dates, and Let's Encrypt has stated it will not revoke them as part of this transition. The last 90-day certificates are expected to expire around May 11, 2027.

The primary motivation behind this move is to enhance overall web security. Shorter certificate lifetimes limit the window of opportunity for attackers if a private key is compromised or if a certificate is issued erroneously. This aligns with a broader industry trend toward decreasing the validity periods of public TLS certificates, a shift that has been discussed and implemented by various Certificate Authorities and industry bodies, including the CA/Browser Forum's plan to reduce maximum validity to 47 days.

To facilitate this transition, Let's Encrypt will begin issuing 64-day certificates in its staging environment on October 14, 2026. This allows administrators to test their renewal processes and ensure compatibility with the new shorter lifespans before the production change. The organization strongly recommends the use of ACME Renewal Information (ARI), a feature within the ACME protocol, which enables automated clients to dynamically schedule renewals based on instructions from the Certificate Authority, rather than relying on fixed calendar dates.

For systems not fully supporting ARI, Let's Encrypt advises renewing certificates at approximately two-thirds of their lifetime. For a 64-day certificate, this translates to renewing around day 43. Administrators are urged to review their automation scripts, cron jobs, and runbooks for any hardcoded renewal values (such as 83, 80, or 60 days) that were likely set for the previous 90-day standard, and update them accordingly. This proactive adjustment will also prepare systems for the further reduction to a 45-day default planned for February 16, 2028.

In addition to certificate lifetimes, Let's Encrypt is also reducing the authorization reuse period from 30 days to 10 days, with a further reduction to seven hours planned for 2028. This change affects how long a previous domain control validation can be reused for subsequent certificate requests. While most subscribers are unlikely to be impacted unless their ACME setup specifically relies on extended authorization reuse, it's a factor to consider for automated certificate management.

Let's Encrypt has clarified that this change will not affect its rate limits or the underlying ACME endpoints and certificate issuance chains. However, operators are encouraged to test their entire certificate workflow, including deployment and service reloads, not just the renewal process. Ensuring that renewed certificates are correctly deployed across all servers and that monitoring systems verify the served certificate after reloads is crucial.

The move to shorter certificate lifetimes underscores the increasing importance of robust, automated certificate lifecycle management. As the window for renewal shrinks, dependable automation becomes paramount to prevent service disruptions and maintain continuous web security. The initiative aims to create a more resilient and secure internet by minimizing the potential impact of compromised keys and misconfigurations.

Synthesized by Vypr AI