Let’s Encrypt Will Reduce SSL/TLS Certificate Validity to 64 Days in 2027
Let’s Encrypt will reduce the validity period of its free SSL/TLS certificates from 90 days to 64 days starting February 10, 2027. The change is designed to strengthen web security and encourage website owners to rely on automated certificate renewal.
ACME clients that support ARI (ACME Renewal Information) can prepare for the change. Website administrators who still depend on hard-coded renewal schedules or manual certificate updates should update their processes before February 2027 to avoid unexpected certificate expiration.
Let’s Encrypt Will Test 64-Day Certificates
Starting October 14, Let’s Encrypt will begin testing certificates with a 64-day validity period. Interested users can test their certificate-management systems before deploying the shorter-lived certificates in production.
Why Are Let’s Encrypt Certificates Getting Shorter?
Before Let’s Encrypt launched in early 2016, SSL/TLS certificates were often issued for one to three years. Let’s Encrypt introduced 90-day certificates to encourage renewal automation, which was not widely used at the time.
Shorter certificate lifetimes can limit the impact of private-key theft, certificate misconfiguration, or incorrect issuance. If a certificate is compromised or misassigned, reducing its validity period limits how long it can remain usable.
The 64-day certificate period continues this approach. Let’s Encrypt has also set a 45-day default validity period for 2028, further reducing the time certificates remain active.
ACME Automation Will Become More Important
Like the original 90-day rollout, the shorter certificate window is intended to move more websites toward full ACME automation.
ARI allows certificate authorities to provide renewal guidance to ACME clients, including information about when certificates should be renewed. However, many deployments still rely on scripted refresh schedules triggered at a fixed interval, such as “60 days before expiration.”
Administrators should review their certificate-management systems and ensure that renewals are automated and compatible with the upcoming 64-day validity period.
Source: arstechnica.com


