Let’s Encrypt Cuts TLS Certificate Lifetimes From 90 to 64 Days Starting February 2027

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Let’s Encrypt will cut its default TLS certificate lifetime from 90 days to 64 days on February 10, 2027, giving website operators less time between renewals.

The change applies to certificates issued or renewed from that date, while subscribers can still choose shorter certificate profiles offering 45 days or roughly six days.

Let’s Encrypt Certificate Lifetime

According to the October 7 announcement published by Let’s Encrypt, the nonprofit certificate authority confirmed the schedule. Existing certificates will remain valid until their normal expiry dates, and Let’s Encrypt will not revoke them as part of the transition. It expects the final 90-day certificate to expire on May 11, 2027.

The shorter lifetime limits how long a certificate can remain trusted after a private key is stolen or a certificate is issued incorrectly. It also makes reliable renewal systems more important, especially for teams still using fixed schedules or manual steps.

The move is part of the wider shift toward shorter public TLS certificate lifetimes. Cybersecurity News previously covered the CA/Browser Forum’s plan to reduce maximum validity to 47 days.

Let’s Encrypt is moving faster, with its default profile set to 45 days on February 16, 2028, as outlined in its earlier certificate lifetime roadmap.

Let’s Encrypt will start issuing 64-day certificates in its staging environment on October 14, 2026. Administrators can use this test service to check renewal behavior before the production change.

Staging certificates are not trusted by browsers and should not replace certificates on live websites. For automated setups, the key feature is ACME Renewal Information, or ARI. ACME is the protocol used to request and renew certificates automatically.

ARI lets Let’s Encrypt tell a supported client when to renew, helping it adjust to shorter lifetimes without relying on a fixed calendar. Administrators should check their client’s documentation to confirm ARI support. When ARI isn’t available, Let’s Encrypt recommends renewing at about two-thirds of the certificate’s lifetime.

For a 64-day certificate, that means around day 43, rather than waiting until the old 60-day renewal point. The authority also recommends searching cron jobs, wrapper scripts, and runbooks for hardcoded values such as 83, 80, or 60.

These numbers may reveal renewal rules designed around 90-day certificates. Updating those rules now also prepares systems for the 45-day default planned for 2028.

Alongside certificate validity, Let’s Encrypt will reduce authorization reuse from 30 days to 10 days. This is the period during which an earlier domain control check can support another certificate request without repeating that check.

The reuse period will fall to seven hours in 2028. Let’s Encrypt says this supports upcoming validation rules and removes the need for separate Certificate Authority Authorization rechecks on older validation data.

Most subscribers will not need changes unless their ACME setup specifically depends on authorization reuse. Rate limits will not change because of the shorter lifetimes, according to Let’s Encrypt’s rate limit guidance. ACME endpoints and certificate issuance chains will also remain unchanged.

Operators should test the full certificate workflow, including deployment and service reloads, rather than checking renewal alone. Teams managing many websites should also confirm that renewed certificates reach every server and that monitoring checks the certificate actually served to users after each reload. Alerts for failed renewals can help teams catch problems before expiry.

The practical priority is dependable automation that keeps certificates current as renewal windows shrink.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Let’s Encrypt Cuts TLS Certificate Lifetimes From 90 to 64 Days Starting February 2027 appeared first on Cyber Security News.