Let’s Encrypt has announced a significant change to its SSL/TLS certificate policy, reducing the lifetime of its free certificates from 90 days to 64 days, effective February 10, 2027. This adjustment aims to enhance security by encouraging more frequent renewals and automation among users. Administrators utilizing modern ACME clients that support the ACME Renewal Information (ARI) protocol should find the transition seamless, while those relying on manual renewal processes will need to adapt before the new policy takes effect.
The testing phase for the 64-day certificates will commence on October 14, allowing interested users to opt in and evaluate their systems ahead of the official rollout. This move follows Let’s Encrypt’s original strategy, which began in 2016 with 90-day certificates to promote automated renewals and mitigate risks associated with long-lived certificates.
Historically, SSL/TLS certificates were issued for periods ranging from one to three years, which posed security risks, particularly in cases of private key theft. By shortening the validity period, Let’s Encrypt aims to minimize potential damage from compromised certificates and encourage broader adoption of HTTPS across the web. The decision to further reduce the certificate lifespan to 64 days reflects a commitment to ongoing security improvements, with plans for even shorter lifetimes, including a proposed 45-day default in 2028.
This initiative not only reinforces the importance of automation in certificate management but also aligns with the broader industry trend towards tighter security protocols. The ACME protocol, particularly with the integration of ARI, facilitates timely renewals by allowing the certificate authority to communicate directly with clients about renewal timelines. However, many users still rely on outdated scripted processes that do not leverage this capability, underscoring the need for modernization in certificate management practices.
As the cybersecurity landscape evolves, Let’s Encrypt’s proactive measures serve as a reminder of the critical need for organizations to adopt automated solutions for SSL/TLS certificate management. The shift to shorter certificate lifetimes is a strategic move to enhance security and streamline operations, ultimately benefiting the broader internet ecosystem.
For further details, refer to Ars Technica.


