Computing

Let’s Encrypt to Shorten Free SSL Certificate Lifetimes to 64 Days from February 2027

Tendela Briefing ·
0 views · 0 Comments
Let’s Encrypt to Shorten Free SSL Certificate Lifetimes to 64 Days from February 2027

Image: Ars Technica · Source

Let’s Encrypt will reduce its free SSL/TLS certificate lifespan from 90 to 64 days starting February 2027, encouraging automated renewals and improving security. Testing begins in October 2026.

Let’s Encrypt has announced plans to shorten the validity period of its free SSL/TLS certificates from the current 90 days down to 64 days, effective February 10, 2027. This change aims to enhance web security by limiting the window of vulnerability if a private key is compromised and by promoting fully automated certificate renewal processes among website administrators.

The initiative continues Let’s Encrypt’s original mission from its 2016 launch, which disrupted traditional certificate validity norms. Previously, certificates commonly had one to three year lifetimes, which posed security risks and slowed HTTPS adoption. By initially imposing 90-day certificates, Let’s Encrypt forced the introduction of renewal automation, reducing risks associated with long-lived certificates.

This latest reduction to 64 days reinforces that approach, with expectations to further reduce lifetimes to 45 days in 2028. Alongside this, Let’s Encrypt is compressing validation periods, cutting authorization reuse from 30 days to 10 days by February 2027, and eventually down to seven hours by 2028. These steps are intended to streamline certificate issuance and decrease reliance on cached validation data.

To ease the transition, testing of 64-day certificates will begin on October 14, 2026, allowing web administrators to verify their renewal systems ahead of the deadline. Let’s Encrypt advises users to ensure their ACME clients support ACME Renewal Information (ARI), which provides renewal timing data dynamically. Administrators relying on manual or fixed-schedule renewal scripts are urged to update them to prevent unexpected certificate expirations.

Best practices recommended include examining renewal processes for hardcoded intervals tailored to the old 90-day schedule—such as 83, 80, or 60 days before expiration—and adjusting these to fit the new 64-day window. Setting up notifications for renewal failures or expirations is also advised.

With roughly four months before the change takes full effect, Let’s Encrypt emphasizes the importance of adaptation to maintain uninterrupted HTTPS service. The organization’s progressive tightening of certificate lifetimes and validation periods signals an industry trend toward heightened security and more efficient automated certificate management.

Illustration of a padlock over a glowing digital data panel.
Illustration of a padlock over a glowing digital data panel. · Source ↗
Photo of Nick Indge
Photo of Nick Indge · Source ↗

Sources and original reporting

Source: Ars Technica
Read the original source ↗

Comments (0)

No comments yet. Start the discussion.

Write a comment

Comments are published after moderation. Your name and comment will be visible publicly. Account