AI News Feed
Market watch
Cybersecurity

Let's Encrypt to Cut Free Certificate Lifetimes to 64 Days Starting February 2027

Let's Encrypt will shorten its free SSL/TLS certificate lifetimes from 90 days to 64 days beginning February 10, 2027, with opt-in testing of the shorter certificates to start on October 14, 2026.

Administrators already running modern ACME clients that support ACME Renewal Information, or ARI, should see the change take effect without disruption, Ars Technica reported. Those who still depend on hardcoded renewal schedules or manual renewal processes will have until next winter to update their systems, otherwise their certificates will begin expiring unexpectedly.

Before the production switch, Let's Encrypt will begin testing 64-day certificates on October 14, 2026. Users who want to check their own setups ahead of time can opt in to the test period.

Let's Encrypt launched in early 2016 with 90-day certificates, a marked change from the practice that preceded it, when certificates were frequently issued for periods of one to three years. The shorter validity was intended to force renewal automation that did not previously exist.

According to Ars Technica, shorter certificate validity periods limit the exposure created by private key thefts and helped accelerate HTTPS adoption across the web.