arstechnica.com 8 Oct 2026, 19:57 UTC

Let’s Encrypt will cut certificate lifetimes to 64 days in 2027

CyberSIXT Evidence Panel Source marked as original reporting

LET’S Encrypt plans to reduce the lifetime of free SSL/TLS certificates from 90 days to 64 days, with the new 64‑day window taking effect from 10 February 2027. The move continues the organisation’s drive toward automated certificate management.

Administrators already using modern ACME clients that support ARI (ACME Renewal Information) should see a seamless transition, while those relying on fixed renewal schedules or manual processes are urged to audit and update their workflows before certificates begin expiring unexpectedly. Testing of the 64‑day certificates will begin on 14 October 2026, and users can opt in to test their setups before production deployment.

The article notes additional changes and guidance for operators: reduce renewal targets previously used for 90‑day certificates (such as 83, 80 and 60) to reflect the new 64‑day expiry, verify that ACME clients support ARI, and ensure renewal notifications are in place in case of expiration or renewal failures.

A broader shift is described, with authorization reuse periods shrinking from 30 days to 10 days, and ultimately to seven hours by 2028, aimed at eliminating reliance on cached validation data and further tightening security. By rolling out shorter certificate lifetimes, Let’s Encrypt seeks to minimise the impact of compromised or misissued certificates, while nudging the ecosystem toward fully automated renewal processes.

View full article

Article by CyberSIXT