Let’s Encrypt, the certificate authority that gives away the SSL/TLS certificates behind HTTPS connections, said on Wednesday that it would shorten their default lifetime to 64 days from 90 days, starting Feb. 10, 2027.
Any certificate issued or renewed on or after that date will be good for 64 days unless the subscriber asks for an even shorter one, 45 or six days, options the group had already announced, according to its announcement. Certificates already in use won’t be revoked. The last 90-day certificate should expire on May 11, 2027.
The people with work to do are administrators who still renew by hand or on a fixed timetable. Sites running modern ACME clients that support ARI, short for ACME Renewal Information, shouldn’t notice the change, Nick Indge wrote in Ars Technica, because ARI lets the certificate authority tell the client when it’s time to renew. Many setups still use scripts that fire at a set offset, such as 60 days before expiration. For those, February is the deadline. After that, certificates could start expiring before anyone expects them to.
Let’s Encrypt told operators with fixed schedules to switch to renewing at about two-thirds of a certificate’s lifetime. Those who aren’t sure how their renewals are set up should search cron jobs, wrapper scripts and runbooks for hard-coded numbers like 83, 80 or 60, the group said.
Testing starts sooner. On Oct. 14, Let’s Encrypt will move its staging environment to 64-day certificates, so operators can opt in and check their setups before the production change.
A second, quieter change is coming too. The period during which a domain validation can be reused will drop to 10 days from 30, and to seven hours in 2028. Let’s Encrypt said the cut was meant to comply with a reduction in maximum validation reuse periods due in 2029 and to remove the need for what it called “CAA rechecking.” Rate limits, ACME endpoints and issuance chains will stay the same, the group said.
Let’s Encrypt has pushed in this direction since it started. Before its launch in early 2016, certificates were often issued for one to three years. The service began with 90-day certificates to force site operators to automate renewals, which few did at the time, and the shorter terms also helped speed the spread of HTTPS.
The reasoning hasn’t changed. A certificate that expires sooner does less harm if its private key is stolen or if it was issued in error, and Let’s Encrypt said shorter lifetimes cut the risk of both key compromise and mis-issuance.
Companies that make renewal software have started warning customers. Certify The Web, which makes a certificate manager for Windows, posted a notice about the change on its support forum.
The 64-day term is an interim step. Let’s Encrypt plans to make 45 days the default in 2028.
