Back
Let's Encrypt to Cut Free SSL/TLS Certificate Lifetimes to 64 Days in February 2027
SiTech AI Team3 min read

Let's Encrypt to Cut Free SSL/TLS Certificate Lifetimes to 64 Days in February 2027

Let's Encrypt will shorten free SSL/TLS certificate lifetimes from 90 days to 64 days starting February 10, 2027. Testing begins October 14, giving administrators about four months to verify their renewal automation.

Shorter Certificates, Tighter Security

Let's Encrypt is reducing the lifetime of its free SSL/TLS certificates from 90 days to 64 days, with the change taking effect on February 10, 2027. The certificate authority said the move continues a push toward tighter security that began when the service launched in early 2016, replacing certificates that were often valid for one to three years with 90-day terms designed to force renewal automation.

Shorter validity periods limit the damage from private key thefts and misissued certificates, and Let's Encrypt said lifespans will keep shrinking, with 45-day defaults planned to follow in 2028.

Automation Is the Goal

The shortened windows are intended to push users toward full ACME automation. The ACME protocol, specifically ACME Renewal Information (ARI), lets the certificate authority tell clients when it is time to renew. Let's Encrypt said administrators already running modern ACME clients with ARI support should see a seamless transition, while those relying on hardcoded renewal schedules or manual processes must update before February or risk certificates expiring unexpectedly.

Many deployments still use scripted updates at fixed offsets, such as renewing 60 days before expiration. Let's Encrypt recommends auditing cron jobs and runbooks to renew at two-thirds of the certificate lifespan, and searching for hardcoded renewal targets like 83, 80, and 60, which were common under the 90-day model.

Testing and Validation Changes

Starting October 14, Let's Encrypt will begin testing 64-day certificates, and interested users can opt in to test their setups before production goes live. Administrators have about four months to verify renewal automation before the February 10 deadline.

The organization is also compressing validation timelines. Authorization reuse periods will shrink from 30 days to 10 days, and eventually to seven hours by 2028, a step Let's Encrypt said should eliminate the need for CAA rechecks. Most operators will not notice the change unless their ACME clients depend on cached validation data.

Industry-Wide Pressure

The shift reflects broader industry mandates. According to discussion following the announcement, the CA/Browser Forum, a group of major browser vendors and certificate authorities, has mandated steadily shorter maximum certificate lifetimes. Under that schedule, the maximum TLS certificate lifetime drops from 398 days to 200 days on March 15, 2026, to 100 days on March 15, 2027, and to 47 days on March 15, 2029. Commenters also flagged appliance vendors that require certificates to be replaced through a web interface as a pain point for IT departments.

Sources: Arstechnica

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.