Let's Encrypt is reducing free SSL/TLS certificate lifetimes from 90 days to 64 days starting February 10, 2027. Administrators using modern ACME clients with ARI (ACME Renewal Information) will experience seamless updates, while those relying on hardcoded or manual renewal schedules must upgrade by the deadline to avoid unexpected expirations.
Testing begins October 14, 2026, with opt-in availability for users to validate their configurations before production deployment. Previously, certificates lasted 1-3 years, but Let's Encrypt introduced 90-day terms in 2016 to drive automated renewal practices and enhance web security.
Shorter validity periods minimize risks from private key compromises and accelerate HTTPS adoption. The 64-day reduction continues this security-focused approach, with plans for 45-day defaults in 2028. The ACME protocol and ARI enable real-time renewal notifications from the certificate authority, though many systems still use fixed-interval scripts that don't adapt to actual renewal needs.
Source: Ars Technica · Summarized by HeadlinesBriefing