Let's Encrypt: 64-Day Certificate Lifetimes Coming Feb 2027
17 hours ago
- From February 10, 2027, default certificate lifetime becomes 64 days, with optional shorter lifetimes of 45 or 6 days.
- Last 90-day certificate will expire on May 11, 2027; valid certificates are not revoked as part of the process.
- Staging environment switches to 64-day certificates on October 14, 2026 for testing.
- If renewals are automated with ARI support, no action needed; otherwise, update hard-coded renewals to approximately 2/3 of lifetime.
- Authorization reuse period reduces from 30 days to 10 days, and will further shrink to 7 hours in 2028 to comply with future requirements.
- This change presents an opportunity to automate certificate management and add alerting for renewal failures.
- Rate limits and ACME endpoints are unaffected.
- Shorter lifetimes reduce risk of key compromise and mis-issuance, advancing global web security.