hn.today

Let's Encrypt: 64-Day Certificate Lifetimes By Default Coming Feb 2027

letsencrypt.org14 points9 comments
Screenshot of Let's Encrypt: 64-Day Certificate Lifetimes By Default Coming Feb 2027

Let’s Encrypt will make 64-day certificate lifetimes the default for all subscribers starting February 10, 2027; any certificate issued or renewed on or after that date will be valid for 64 days, and the last 90-day certificate is expected to expire on May 11, 2027. Staging will switch to 64-day issuance on October 14, 2026 for testing. Subscribers can still choose shorter defaults (45 or 6 days as previously announced) and no valid certificates will be revoked as part of the change. Rate limits, ACME endpoints, and issuance chains remain unchanged.

Operationally, automated renewals should be fine if ACME Renewal Info (ARI) is supported by the client, because ARI lets Let’s Encrypt tell clients when to renew; operators with hard-coded renewal dates must change them to renew at roughly two-thirds of the lifetime and should search cron jobs and scripts for common hard-coded numbers (83, 80, 60). Authorization reuse will shrink from 30 to 10 days now and to seven hours in 2028 to comply with upcoming validation-reuse limits and avoid CAA rechecking; most clients won’t need changes unless they rely on reuse. The change aims to reduce key-compromise and mis-issuance risk, and recipients are urged to test in staging, automate reload/deployment and add renewal alerts; community forum and documentation are available for help.

Read on letsencrypt.org9 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.