THURSDAY, OCTOBER 8, 2026|No. 17981
Technology · Security

Let's Encrypt to Shorten Certificate Lifetimes to 64 Days in 2027

Let's Encrypt is reducing the lifespan of its SSL/TLS certificates from 90 days to 64 days starting February 10, 2027, as part of an ongoing effort to enhance internet security.

A padlock icon symbolizing digital security and SSL certificates.
A padlock icon symbolizing digital security and SSL certificates.
1 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
0 countries
Related coverage

Let’s Encrypt is continuing a push toward tighter security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting February 10, 2027. For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the change should be seamless. For those still relying on hardcoded renewal schedules or manual processes, February will be the deadline to update before certificates start expiring unexpectedly.

Starting on October 14, Let’s Encrypt will begin testing the 64-day certificates, and interested users can opt in to test their setups before production goes live.

Prior to Let’s Encrypt’s launch in early 2016, certificates were often issued for as long as one to three years. The service started with 90-day certificates to force renewal automation that didn’t previously exist. Shorter certificate validity periods limited vulnerabilities from private key thefts and encouraged accelerated HTTPS adoption across the web.

This move shook industry norms at the time, but by limiting the certificate lifetime, the certs are less likely to cause damage if compromised or assigned in error. The move down to 64 days continues this logic, and the lifespans will only continue to get shorter as time goes on, with 45-day defaults planned to follow in 2028.

Just as the initial rollout of Let’s Encrypt aimed to push users toward HTTPS, the shortened certificate windows are aimed at moving users to full ACME automation. The ACME protocol, and, more specifically, ARI (ACME Renewal Information), allows the certificate authority to tell the client when it’s time to renew. Although ARI does this, many deployments are still stuck on scripted update intervals that trigger at fixed offsets like “60 days before expiration.”

Let’s Encrypt is getting this information out now to warn these users to audit their cron jobs and runbooks to automatically renew at two-thirds their lifespan and, in doing so, prepare for the additional shrinkage of 45-day certificates planned for 2028.

What web administrators can do now

  • The company specifically recommends users search for hardcoded renewal numbers like 83, 80, and 60 (common previous renewal targets for 90-day certificates) and update them to renew prior to expiration at the new 64-day limit.
  • Verify your ACME client supports ARI; if not, update renewal scripts.
  • Ensure notifications are set in the event of certificate expiration or renewal failures
  • Take advantage of the October 14 testing period before the official rollout.

Alongside certificate lifetimes, Let’s Encrypt is also compressing validation timelines. Authorization reuse periods will shrink from 30 days to 10 days, and eventually to seven hours by 2028. This step should eliminate the need for CAA rechecks. Most operators won’t notice the change unless their ACME clients depend on cached validation data.

Administrators will have about four months to test their renewal automations before the February 10 deadline, or risk downtime when the deadline arrives.

Nick Indge Senior Technology Reporter

Nick Indge is a Senior Technology Reporter at Ars Technica covering hardware, embedded systems, and self-hosted infrastructure. A former security investigator turned tech writer, he writes to help readers escape subscription traps and regain ownership of their digital lives. He lives in Chicagoland with his family and a goofball husky.

No mention of all this being driven by the CA/B working group? Because those changes are what's driving this.

Biggest problem with this for many IT departments is foot-dragging appliance vendors who want you to click through some web interface to replace a cert and don't provide another method. Real PITA.

Was going to say much the same - CA/B, for those who don't know, is the "CA/Browsers Forum" - a group of the major browser vendors + CAs, and the Browser Vendors forced a mandate on the CA/Browsers Forum that the Browsers will over time treat certificates as invalid after shortening periods of certificate lifetimes (they have and are continuing to step down the lifetime lengths on a schedule).

I'm positive that Let's Encrypt was fully on board with this change (after all, they pioneered the exact kind of automation which will make this easy to achieve), but they are reducing down to 47 days, because that is the maximum validity that Browsers will soon allow for a CA issued certificate.

Nice post from digicert explaining the schedule of changes for lifetimes.

Here's the bit of the schedule of main interest:

The maximum certificate lifetime is going down:

  • From today until March 15, 2026, the maximum lifetime for a TLS certificate is 398 days.
  • As of March 15, 2026, the maximum lifetime for a TLS certificate will be 200 days.
  • As of March 15, 2027, the maximum lifetime for a TLS certificate will be 100 days.
  • As of March 15, 2029, the maximum lifetime for a TLS certificate will be 47 days.

Also, really excellent talk about the current state of https from the NDC Toronto conference:

Spoiler content hidden.

PAN's pipeline reviewed approximately 1 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →

Earlier on PAN

More in Technology →