hn.today

Let's Encrypt: 64-Day Certificate Lifetimes Coming Feb 2027

letsencrypt.org38 points10 comments
Screenshot of Let's Encrypt: 64-Day Certificate Lifetimes Coming Feb 2027

Let’s Encrypt will change its default certificate validity to 64 days for all new issues and renewals on or after February 10, 2027; subscribers can still choose shorter defaults (45 or 6 days). Certificates issued or renewed on that date or later will carry the 64-day lifetime, with the final 90-day certs expiring on May 11, 2027; valid certificates will not be revoked. Staging will switch on October 14, 2026 for testing, and users with automated renewal that support ACME Renewal Info (ARI) require no changes. Administrators who hard-code renewal dates should update jobs to renew at roughly two-thirds of the lifetime (e.g., replace common hard-coded values like 83, 80 or 60), both to handle 64-day lifetimes and to prepare for a planned default of 45 days in 2028.

Authorization reuse will drop from 30 days to 10 days now and is scheduled to shrink further to seven hours in 2028 to comply with a 2029 validation-reuse limit and to eliminate CAA rechecking. Unless an ACME client is explicitly built to depend on reuse windows, no client modifications are needed. Rate limits, ACME endpoints, and issuance chains are unchanged. The change is presented as a security improvement to reduce key-compromise and mis-issuance risk; implementers are encouraged to automate reload/deployment and add alerting for renewal failures, and to consult staging, documentation, or the community forum if problems arise.

Read on letsencrypt.org10 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.