Let's Encrypt moving to 64-day certificate lifetimes in 2027
Let's Encrypt , the nonprofit that provides free TLS certificates for millions of sites, has announced that it will be moving to certificates with 64-day lifetimes on February 10, 2027: This means that any certificate we issue or renew on and after that date will have a 64 day validity period, and we expect the last 90-day certificate to expire on May 11, 2027. We will not revoke valid…
Let's Encrypt plans to reduce the lifetimes of its free SSL/TLS certificates from 90 days to 64 days, effective February 10, 2027. This change aims to enhance security by minimizing the window of vulnerability if private keys are stolen. For administrators who have already adopted modern ACME clients supporting Automatic Renewal Information (ARI), the transition to the new shorter certificate lifetimes should be straightforward.
However, those still relying on manual renewal schedules or hard-coded renewal dates must update their systems before winter of 2026, as that will be the deadline for avoiding unexpected certificate expirations. Starting October 14, 2026, Let's Encrypt will begin testing the new 64-day certificates, and interested users can participate in testing their configurations before the change becomes official.
Before Let's Encrypt began issuing certificates in early 2016, certificates were often granted for prolonged periods of 1 to 3 years. The service initially introduced 90-day certificates to encourage the automation of certificate renewal processes that were not common at the time. Shorter validity periods for certificates have not only reduced the risk associated with private key theft but have also accelerated the adoption of HTTPS across the web.
Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.