Let’s Encrypt to reduce SSL/TLS certificate lifetimes to 64 days starting February 2027

Published:

Let’s Encrypt has announced a significant change to its SSL/TLS certificate policy, reducing the lifetime of its free certificates from 90 days to 64 days, effective February 10, 2027. This adjustment aims to enhance security by encouraging more frequent renewals and automation among users. Administrators utilizing modern ACME clients that support the ACME Renewal Information (ARI) protocol should find the transition seamless, while those relying on manual renewal processes will need to adapt before the new policy takes effect.

The testing phase for the 64-day certificates will commence on October 14, allowing interested users to opt in and evaluate their systems ahead of the official rollout. This move follows Let’s Encrypt’s original strategy, which began in 2016 with 90-day certificates to promote automated renewals and mitigate risks associated with long-lived certificates.

Historically, SSL/TLS certificates were issued for periods ranging from one to three years, which posed security risks, particularly in cases of private key theft. By shortening the validity period, Let’s Encrypt aims to minimize potential damage from compromised certificates and encourage broader adoption of HTTPS across the web. The decision to further reduce the certificate lifespan to 64 days reflects a commitment to ongoing security improvements, with plans for even shorter lifetimes, including a proposed 45-day default in 2028.

This initiative not only reinforces the importance of automation in certificate management but also aligns with the broader industry trend towards tighter security protocols. The ACME protocol, particularly with the integration of ARI, facilitates timely renewals by allowing the certificate authority to communicate directly with clients about renewal timelines. However, many users still rely on outdated scripted processes that do not leverage this capability, underscoring the need for modernization in certificate management practices.

As the cybersecurity landscape evolves, Let’s Encrypt’s proactive measures serve as a reminder of the critical need for organizations to adopt automated solutions for SSL/TLS certificate management. The shift to shorter certificate lifetimes is a strategic move to enhance security and streamline operations, ultimately benefiting the broader internet ecosystem.

For further details, refer to Ars Technica.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

DARPA’s Quantum Benchmarking Initiative advances four organizations to final testing stage for utility-scale quantum computing

Four organizations have advanced to the final stage of the Defense Advanced Research Projects Agency's (DARPA) Quantum Benchmarking Initiative (QBI), which aims to assess...

16 malicious Firefox extensions impersonate Rabby and OKX wallets to steal cryptocurrency recovery phrases

Cybersecurity researchers have identified 16 malicious Mozilla Firefox extensions designed to impersonate popular cryptocurrency wallets, specifically Rabby and OKX, with the intent to steal...

US withdrawal of B-1 bombers from RAF Fairford highlights need for enhanced base defenses against drone threats

In a significant operational shift, the United States has withdrawn a dozen B-1 Lancer bombers from RAF Fairford in southern England, a move prompted...

Web3 command-and-control evolution enhances cloud supply chain attack strategies, reveals Unit 42 analysis

Recent analysis by Unit 42 reveals a significant evolution in the command-and-control (C2) strategies employed by threat actors, particularly in the context of cloud...