Let's Encrypt will change its default certificate lifetime from 90 to 64 days on February 10, 2027.
Automated renewals are expected to need little or no intervention, but fixed-interval renewal jobs and scripts should be reviewed.
Existing certificates remain valid until expiry; no valid certificates will be revoked during the transition.
The new duration will apply to certificates issued or renewed on or after February 10. Those already issued will remain valid until their expiration date. Let's Encrypt estimates that the last 90-day certificate will expire on May 11, 2027, and confirms that it will not revoke valid certificates during the transition.
The shorter duration limits the time a certificate that has been issued incorrectly or has fallen into the wrong hands can be used. 64-day certificates will be available in Let's Encrypt's test environment starting October 14, 2026.
What administrators need to check
Let's Encrypt expects that those who have auto-renewal set up will need to make few or no changes. According to the company, tools that support the ACME Renewal Info feature will be ready for the transition. This feature tells tools when certificates need to be renewed.
Those relying on scheduled tasks or scripts with fixed renewal intervals should check their settings. Let's Encrypt recommends scheduling renewal after about two-thirds of the validity period has passed. Fixed intervals, such as 83, 80, or 60 days, may not work reliably with certificates with shorter expiration dates.
The time frame in which a previous check can be reused for a website will also be reduced from 30 to 10 days. In 2028, it will be reduced further, to seven hours. Most users will not need to change anything, unless their tools rely on re-running older checks.
Let's Encrypt plans to reduce the default validity period to 45 days in 2028. The transition will not change the limits for issuing certificates, the points of contact for issuing them, or the way certificates are linked together.
Top comments (1)
tr.ee/dev-to