Interestana
Home/News/Let's Encrypt Reduces Certificate Lifetimes to 64 Days
Ars Technica••2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Let's Encrypt Reduces Certificate Lifetimes to 64 Days

Let's Encrypt Reduces Certificate Lifetimes to 64 Days

Let's Encrypt is implementing a significant security enhancement by reducing the validity period of its free SSL/TLS certificates from the current 90 days to 64 days. This change is scheduled to take effect on February 10, 2027. The organization, which provides free digital certificates that enable encrypted connections (HTTPS) for websites, aims to further bolster web security through this measure. Shorter certificate lifetimes are designed to limit the window of vulnerability should a private key be compromised, thereby reducing the potential impact of security breaches. This initiative also serves to accelerate the adoption and consistent use of HTTPS across the internet.

For website administrators and system operators who are already utilizing modern ACME (Automated Certificate Management Environment) clients that support ARI (ACME Renewal Information), this transition is expected to be seamless. ARI allows clients to automatically manage certificate renewals and updates without manual intervention. However, administrators who are still relying on outdated methods, such as hardcoded renewal schedules or manual certificate management processes, will need to update their systems before the February 10, 2027 deadline. Failure to do so could result in certificates expiring unexpectedly, leading to website downtime and security warnings for visitors.

To facilitate a smooth transition and allow users to prepare, Let's Encrypt will commence testing the 64-day certificates on October 14, 2026. Interested parties will have the opportunity to opt-in to these testing programs to verify their setups and ensure compatibility before the production rollout. This phased approach is intended to identify and resolve any potential issues proactively.

This move represents a continuation of Let's Encrypt's long-standing commitment to improving web security since its launch in early 2016. At its inception, certificates were often issued for much longer periods, sometimes one to three years. Let's Encrypt initially launched with 90-day certificates specifically to encourage the adoption of automated renewal processes, which were not widely prevalent at the time. The subsequent reduction to 64 days signifies a further evolution in best practices for certificate management, prioritizing security and rapid response to potential threats over extended validity periods.

Original source — read the full reporting at the publisher:

Read on Ars Technica

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next