Security/ lets-encrypt · tls-certificates · security · https

Let's Encrypt Cuts Certificate Lifespans to 64 Days

The free certificate authority will shrink SSL/TLS validity from 90 to 64 days starting February 2027, with testing beginning this month.

Let's Encrypt is cutting free HTTPS certificate lifespans from 90 days to 64, effective February 10, 2027.

The nonprofit certificate authority starts testing the shorter 64-day certificates on October 14, 2026, letting administrators opt in and check their renewal setups before the cutover. Sites using modern ACME clients that support ACME Renewal Information, or ARI, should barely notice the switch. Anyone still relying on hardcoded renewal schedules or manual certificate management has until next winter to fix that, or certificates will start expiring without warning.

Shorter lifespans shrink the window a stolen private key stays useful, and they keep forcing the kind of automation that makes HTTPS easy to maintain at scale. It's also a reminder of how much the web's security baseline has shifted: ten years ago, certificates routinely lasted one to three years, and renewing by hand was normal.

Let's Encrypt has been shrinking that window since its 2016 launch forced 90-day certificates on an industry used to multi-year renewals. Sixty-four days is just the next notch, not a sudden swerve.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →