Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Let’s Encrypt has made 6-day IP-based TLS certificates Generally Available

## Cybersecurity: Updates on Let's Encrypt TLS Certificates

Cybersecurity: Updates on Let's Encrypt TLS Certificates

Let's Encrypt, a prominent provider of free TLS certificates, has introduced short-lived and IP address-based certificates for general use. These options became available in early 2026, addressing existing concerns in certificate security.

Short-lived certificates have a lifespan of 160 hours, approximately six and a half days. Users can activate them by selecting the "short-lived" profile in their ACME client. These certificates are designed to enhance security by reducing the risk of key compromise.

Traditional TLS certificates can last up to 90 days, allowing potential exploitation if private keys are leaked. Short-lived certificates mitigate this risk by requiring frequent renewals and reducing reliance on revocation systems such as CRLs and OCSP. This approach limits exposure to compromised keys to a few hours.

Let's Encrypt has made this feature optional. While automated systems can renew short-lived certificates easily via ACME, manual users might prefer maintaining longer certificate lifespans for now. The organization plans to gradually reduce default lifetimes to 45 days over the next several years.

Let's Encrypt, a prominent provider of free TLS certificates, has introduced short-lived and IP address-based certificates for general use.
Hazel Caldwell · Thehackingpost

IP-based certificates enable servers to authenticate TLS connections using raw IP addresses, supporting both IPv4 and IPv6. Unlike domain-based certificates, these are validated through IP address verification methods. Let's Encrypt requires these certificates to be short-lived due to the dynamic nature of IP addresses in environments such as cloud instances and mobile networks.

These certificates are useful for legacy systems without domain names, containerized applications on private networks, and testing environments. Validation involves ACME challenges to verify IP control, often through direct connections.

Advertisement

Security experts consider IP-based certificates beneficial for securing IP-only traffic in hybrid networks, eliminating the need for workarounds like self-signed certificates. They also facilitate tighter key rotation and reduce the need for revocation, which is advantageous for security operations and threat monitoring.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories