Skip to content
ittechwire

Technology news, clearly sourced

  1. Home
  2. Software

Software

Let's Encrypt to make 64-day certificates the default from 10 February 2027

Let's Encrypt will shorten its default certificate lifetime from 90 to 64 days on 10 February 2027 and will start issuing 64-day certificates in its staging environment on 14 October 2026.

ittechwire Editorial3 min readSources: 1
Three keys on a ring on a wooden table, one of them inserted in a brass padlock that is partly visible at the top right
Trougnouf · CC BY 4.0

Key points

  1. 1From 10 February 2027, new and renewed Let's Encrypt certificates will be valid for 64 days by default; subscribers can still opt for 45 or 6 days.
  2. 2Staging switches to 64-day certificates on 14 October 2026; the last 90-day certificates are expected to expire on 11 May 2027, and valid certificates will not be revoked.
  3. 3Clients that use ACME Renewal Info should need no changes, while fixed renewal schedules should move to about two-thirds of the certificate lifetime.
  4. 4Authorization reuse drops from 30 days to 10 days, and to seven hours in 2028, with a 45-day default lifetime also planned for 2028.

Full story

Let's Encrypt plans to cut the default lifetime of its certificates to 64 days starting on 10 February 2027, according to a post on its blog dated 7 October 2026. From that date, every certificate it issues or renews will be valid for 64 days, unless the subscriber has chosen one of the even shorter lifetimes of 45 or 6 days that were announced earlier. Let's Encrypt expects the last of its current 90-day certificates to expire on 11 May 2027 and says it will not revoke certificates that are still valid as part of the switch.

To allow testing, the staging environment will begin issuing 64-day certificates on 14 October 2026, and Let's Encrypt recommends trying the change there before it reaches production. According to the post, subscribers whose renewals are automated through a client that supports ACME Renewal Info (ARI) should not need to act, because ARI lets Let's Encrypt signal to the client when a renewal is due; the client's documentation shows whether ARI is supported. Setups that renew a fixed number of days before expiry should instead be changed to renew at roughly two-thirds of a certificate's lifetime. Let's Encrypt suggests searching cron jobs, wrapper scripts and runbooks for hard-coded values such as 83, 80 or 60, and says this adjustment also prepares for a default lifetime of 45 days in 2028.

Separately, the period for which authorizations can be reused will fall from 30 days to 10 days, and in 2028 it is set to shrink further to seven hours. Let's Encrypt gives two reasons: compliance with a reduction in maximum validation reuse periods due in 2029, and getting rid of what it calls CAA rechecking, under which part of the validation must be repeated once the validation data is older than 7 hours. The post says most users will not have to change anything unless their ACME client was built specifically to depend on validation reuse.

According to Let's Encrypt, rate limits, ACME endpoints and its issuance chains are not affected. The nonprofit says shorter lifetimes lower the risk of key compromise and mis-issuance, and it encourages subscribers to use the transition to automate steps such as reloading and deploying certificates and to set up alerts for failed renewals. It says it expects the move to go smoothly and points anyone who runs into problems to its community forum and documentation.

Why it matters

The change mainly concerns administrators who renew certificates on a fixed schedule: a renewal timer set for 90-day certificates may no longer fit a 64-day lifetime. Let's Encrypt presents 64 days as a step toward a 45-day default in 2028, so updating renewal logic now also covers that next reduction. Setups that rely on ARI, or that renew at about two-thirds of the lifetime, should keep working without changes, according to the post.

Timeline

  1. · Published

Topics#Let's Encrypt#certificates#ACME#web security#automation

Sources

This story draws on the following sources. Read them for full context.

  1. 1Let's Encrypt · Primary source64-Day Certificate Lifetimes Coming Feb 2027letsencrypt.org