Let’s Encrypt to Shorten TLS Certificate Lifespans to 64 Days in 2027
Key Takeaways Let’s Encrypt will reduce the default lifespan of its TLS certificates from 90 to 64 days, effective February 10, 2027. This change aims to enhance security by limiting the...
Key Takeaways
- Let’s Encrypt will reduce the default lifespan of its TLS certificates from 90 to 64 days, effective February 10, 2027.
- This change aims to enhance security by limiting the exposure window for compromised private keys or improperly issued certificates.
- Website operators must ensure their automated renewal systems are robust and consider implementing ACME Renewal Information (ARI) for seamless transitions.
- The authorization reuse period will also shorten significantly, impacting specific ACME setups.
Let’s Encrypt Mandates Shorter TLS Certificate Lifespans for Enhanced Security
In a significant move impacting web security, Let’s Encrypt has announced plans to shorten the default validity period for its TLS certificates. Starting February 10, 2027, all newly issued or renewed certificates will have a maximum lifespan of 64 days, a reduction from the current 90-day standard. This initiative aligns with a broader industry trend toward more frequent certificate renewals, aiming to bolster the overall security posture of the internet.
Table Of Content
While the 64-day default will become standard, subscribers will still have the option to select even shorter certificate profiles, including 45 days or approximately six days, for specific use cases. Existing certificates issued before the February 2027 cutoff will remain valid until their original expiration dates, with no plans for early revocation by Let’s Encrypt.
Driving Factors Behind the Change
The primary motivation for this reduction is to mitigate risks associated with certificate compromise. A shorter certificate lifetime minimizes the window during which a stolen private key or an erroneously issued certificate can be exploited. This proactive measure strengthens the integrity of TLS encryption across the web, making it more resilient against various attack vectors.
This shift also underscores the critical importance of reliable and automated certificate renewal systems. Organizations that currently rely on fixed renewal schedules or manual processes will need to adapt their strategies to accommodate the more frequent renewal cycles. The nonprofit certificate authority confirmed this schedule in an announcement published on Let’s Encrypt on October 7.
This move by Let’s Encrypt is part of a wider industry initiative. The CA/Browser Forum has also discussed plans to reduce the maximum validity of public TLS certificates to 47 days. Let’s Encrypt is progressing even faster, with its roadmap indicating a further reduction to a 45-day default profile by February 16, 2028.
Preparing for the Transition
To facilitate a smooth transition, Let’s Encrypt will begin issuing 64-day certificates in its staging environment on October 14, 2026. This pre-production service allows administrators to rigorously test their renewal mechanisms and ensure compatibility before the change rolls out to the live production environment. It is crucial to remember that staging certificates are not trusted by browsers and are unsuitable for live websites.
A key feature for automated setups is ACME Renewal Information (ARI). ACME, the protocol used for automated certificate requests and renewals, can leverage ARI to receive specific renewal timing instructions from Let’s Encrypt. This capability helps clients adjust to shorter certificate lifetimes dynamically, rather than relying on static, potentially outdated, calendar-based schedules. Administrators should consult their ACME client’s documentation to confirm ARI support. For clients without ARI, Let’s Encrypt advises initiating renewals at approximately two-thirds of the certificate’s total lifetime.
For a 64-day certificate, this translates to renewing around day 43, rather than waiting for the previous 60-day mark. Let’s Encrypt also strongly recommends auditing existing cron jobs, wrapper scripts, and runbooks for any hardcoded renewal values such as 83, 80, or 60. Updating these values now will not only prepare systems for the 2027 change but also for the subsequent 45-day default planned for 2028.
Changes to Authorization Reuse and Other Parameters
In addition to certificate validity, Let’s Encrypt will also reduce the authorization reuse period from 30 days to 10 days. This period defines how long a prior domain control check remains valid to support subsequent certificate requests without requiring a repeated verification. This period is slated to decrease further to just seven hours in 2028. Let’s Encrypt states that this change supports upcoming validation rules and eliminates the need for redundant Certificate Authority Authorization (CAA) rechecks on older validation data.
Most subscribers are unlikely to be impacted by the authorization reuse change unless their ACME setup specifically relies on this feature. Let’s Encrypt has confirmed that rate limits, ACME endpoints, and certificate issuance chains will remain unaffected by these changes, as detailed in their rate limit guidance.
What You Should Do
- Test in Staging: Utilize Let’s Encrypt’s staging environment starting October 14, 2026, to thoroughly test your certificate renewal workflow, including deployment and service reloads.
- Verify ACME Client Support: Check your ACME client’s documentation for support of ACME Renewal Information (ARI) to enable dynamic renewal scheduling.
- Update Hardcoded Values: Audit and update any hardcoded renewal intervals in cron jobs, scripts, or runbooks that might be based on older 90-day certificate lifespans.
- Monitor Certificate Deployment: For organizations managing multiple websites, ensure that renewed certificates are successfully deployed to all servers and that monitoring systems verify the certificate presented to users after each reload.
- Establish Renewal Alerts: Implement robust alerting for failed certificate renewals to proactively identify and address issues before certificates expire and cause service disruptions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.