Let’s Encrypt to introduce 64-day certificates in February 2027 — Ars Technica
Starting February 10, 2027, Let’s Encrypt will reduce the validity period of its free SSL/TLS certificates from 90 to 64 days. The change is intended to strengthen certificate renewal automation and reduce the period during which a compromised or mistakenly issued certificate remains valid, Ars Technica reports.
Testing will begin in October
Starting October 14, 2026, users will be able to take part in testing 64-day certificates before their full launch. For administrators using modern ACME clients with support for ARI — ACME Renewal Information — the transition should proceed without complications, according to the publication.
ARI allows a certificate authority to notify a client when a certificate should be renewed. At the same time, some systems still use scripts with fixed renewal intervals or manual procedures, which may lead to an unexpected certificate expiration after the validity periods change.
More current news is available on the UA.News Telegram channel Telegram.
What administrators should check
Let’s Encrypt recommends checking scripts and cron jobs for hard-coded values of 83, 80, and 60 days, which were often used for 90-day certificates. Administrators should also ensure that their ACME client supports ARI, configure alerts for failed renewals or certificate expiration, and test automation in October.
The authorization reuse period will also be reduced from 30 to 10 days, and to seven hours by 2028. In 2028, Let’s Encrypt plans to move to a standard certificate validity period of 45 days.