8
Rewritten Article:
Let’s Encrypt Reduces SSL/TLS Certificate Validity to 64 Days for Improved Security
Starting February 10, 2027, Let’s Encrypt is enhancing security measures by shortening the validity period of free SSL/TLS certificates from 90 days to 64 days. This change aims to promote renewal automation and reduce potential vulnerabilities for users relying on hard-coded or manual renewal processes.
Testing Phase Beginning October 14th
Beginning on October 14th, Let’s Encrypt will initiate a testing phase for the new 64-day certificates. Users are encouraged to test their certificate setup before transitioning into production to ensure a seamless process.
Evolution of Certificate Validity
Prior to Let’s Encrypt’s launch in 2016, certificates typically had durations ranging from one to three years. The introduction of the 90-day certificate aimed to enforce renewal automation and enhance security across the web. The move towards shorter certificate lifetimes is driven by the goal of limiting vulnerabilities associated with private key theft and promoting widespread HTTPS adoption.
Continued Progress with 64-Day Certificates
Reducing the validity period to 64 days is a strategic step towards enhancing security protocols. By further decreasing certificate lifespans, Let’s Encrypt aims to minimize the potential impact of compromised or misassigned certificates. The default duration is set to decrease to 45 days in 2028, emphasizing the commitment to continuous security improvements.
Transitioning to Full ACME Automation
Similar to Let’s Encrypt’s initial mission of advancing users towards HTTPS adoption, the shift to shorter certificate durations encourages full ACME automation. The implementation of Ali (ACME Update Information) allows certificate authorities to streamline the renewal process by notifying clients when it’s time to renew. While some deployments are still reliant on scripted refresh intervals, the industry is moving towards a more automated and secure certificate management approach.
Source: arstechnica.com












