MeteoalarmOrange Wind Warning issued for Latvia (7 novadi)Alerts →
Friday, 9 October 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 9 October 2026 at 03:30

Let's Encrypt to shorten certificate lifetimes to 64 days

Let's Encrypt, the free SSL/TLS certificate provider, will cut certificate validity from 90 to 64 days starting February 10, 2027. Testing begins October 14, and a 45-day default is planned for later.

Foto: Ars Technica

Let's Encrypt, the service that issues free SSL/TLS certificates used to secure websites with HTTPS, will reduce certificate lifetimes from 90 days to 64 days starting February 10, 2027. The change affects website administrators worldwide and continues a steady push toward tighter security through ever shorter certificate validity.

Testing and preparation

Let's Encrypt will begin testing the 64-day certificates on October 14. Interested users can opt in to check their setups before the change goes into production.

Administrators who already use modern ACME clients supporting ARI (ACME Renewal Information) should see a seamless transition. ACME is the protocol for automated certificate management, and ARI lets the certificate authority tell the client when to renew. Those relying on hardcoded renewal schedules or manual processes will have until February to update, or their certificates will start expiring unexpectedly. Many deployments still use scripts that trigger at fixed offsets, such as 60 days before expiration.

Why lifetimes keep shrinking

Before Let's Encrypt launched in early 2016, certificates were often issued for one to three years. The service began with 90-day certificates to force renewal automation that did not previously exist. Shorter validity limits the exposure from private key theft and encouraged faster HTTPS adoption across the web. A certificate that is compromised or issued in error is also less likely to cause damage if it expires sooner.

The move to 64 days follows the same logic, and lifetimes are expected to keep falling, with a 45-day default planned for 2028. Just as the original rollout pushed users toward HTTPS, the shorter windows are intended to move them to full ACME automation.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category