TECHNOLOGY · VERIFIED DEVELOPMENT
Let's Encrypt Reduces Certificate Lifetimes to 64 Days
WHY IT MATTERS
This change aims to improve security by limiting vulnerabilities from private key thefts and accelerating HTTPS adoption across the web.
What happened
Let's Encrypt is reducing the lifetime of free SSL/TLS certificates from 90 days to 64 days, starting on February 10, 2027. This change aims to improve security by limiting vulnerabilities from private key thefts.
For administrators using modern ACME clients, the transition should be seamless. Those relying on hardcoded renewal schedules or manual processes will need to update before certificates start expiring unexpectedly next winter.
Let's Encrypt will begin testing 64-day certificates on October 14, 2026, and interested users can opt-in to test their setups before production goes live.
PRIMARY SOURCES
Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027
Ars Technica · Nick Indge · Discovery only; Condé Nast copyright terms apply
CORRECTIONS & UPDATES
- Revision 1 · Initial ingestion · Oct 8, 2026, 8:30 PM
- Revision 2 · Source update detected · Oct 8, 2026, 8:30 PM