Let's Encrypt announced it will shorten the validity period for its free SSL/TLS certificates from 90 days to 64 days. This change is scheduled to go into effect on February 10, 2027. This continues a trend of reducing certificate lifetimes to enhance security and promote automation.
System administrators using modern ACME clients that support ACME Renewal Information (ARI) should experience a seamless transition. However, those relying on hardcoded renewal schedules or manual processes will need to update their systems before the February 2027 deadline to prevent unexpected certificate expirations. Testing for the 64-day certificates will begin on October 14, allowing users to opt-in and test their configurations.
The decision to reduce certificate lifetimes is driven by security considerations. Shorter validity periods decrease the window of vulnerability if a private key is compromised or a certificate is issued in error. Let's Encrypt initially launched with 90-day certificates in 2016 to encourage the adoption of automated renewal processes, a significant shift from the previous norm of one-to-three-year certificates.
This reduction also serves to further push users towards full ACME automation, particularly the use of ARI. ARI allows the certificate authority to inform the client when renewal is necessary, moving away from fixed, script-based renewal intervals. Future plans include further reductions, with 45-day defaults anticipated in 2028.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Let's Encrypt will reduce the validity period of its free SSL/TLS certificates from 90 to 64 days, effective February 10, 2027. This change aims to improve security by limiting the impact of compromised keys and to encourage the adoption of automated certificate management protocols like ACME with ARI.