Let’s Encrypt Cutting Certificate Lifespan from 90 Days to 45 Days
Let's Encrypt, a nonprofit certificate authority, has announced an update regarding the issuance of its digital certificates. Starting in 2026, the validity period of Let's Encrypt SSL/TLS certificates will be reduced from 90 days to 45 days, with full…
Let's Encrypt, a nonprofit certificate authority, has announced an update regarding the issuance of its digital certificates. Starting in 2026, the validity period of Let's Encrypt SSL/TLS certificates will be reduced from 90 days to 45 days, with full implementation scheduled for February 2028.
This change aligns with the CA/Browser Forum Baseline Requirements, which set technical guidelines for publicly-trusted Certificate Authorities. The initiative aims to enhance internet security by limiting potential compromise scope and improving certificate revocation effectiveness.
In addition to reducing certificate lifespans, Let's Encrypt will decrease its authorization reuse period from 30 days to 7 hours by 2028. This change will necessitate more frequent domain control validation, although new tools will be introduced to streamline this process.
A Phased Rollout to Minimize Disruption
Let's Encrypt will implement these changes in stages using ACME Profiles, allowing administrators to choose when to adopt new standards. The rollout timeline includes:
May 13, 2026: Launch of the TLS server ACME profile for early adopters and testing, issuing 45-day certificates. February 10, 2027: Default classic profile begins issuing 64-day certificates with a 10-day authorization reuse period. February 16, 2028: Classic profile fully transitions to 45-day certificates with a 7-hour authorization reuse window.
Let's Encrypt, a nonprofit certificate authority, has announced an update regarding the issuance of its digital certificates.
Most users with automated certificate management will experience minimal disruption as changes only take effect upon certificate renewal after each rollout date. Administrators should ensure their automation infrastructure can handle more frequent renewals.
Let's Encrypt recommends using ACME Renewal Information (ARI) for renewal timing. Organizations without ARI should implement renewal schedules approximately two-thirds through the certificate's validity period.
Let's Encrypt is collaborating with the CA/Browser Forum and the IETF to standardize DNS-PERSIST-01, a validation method arriving in 2026. This method allows administrators to configure DNS entries once, simplifying automation for organizations with limited ACME client access.
Administrators are advised to implement monitoring systems to alert them of any unexpected certificate renewal failures. Documentation on monitoring options is available from Let's Encrypt to assist administrators in maintaining visibility.
To stay informed, administrators can subscribe to Let's Encrypt's technical updates mailing list. While shorter certificate lifespans require more frequent renewals, enhanced security and new automation tools aim to reduce operational friction.
Based on reporting by GBHackers.
