Let's Encrypt to Cut Free Certificate Lifetimes to 64 Days in 2027
Testing of the shorter 64-day SSL/TLS certificates will begin on October 14, with opt-in available for users to check their renewal setups.
Let's Encrypt announced it will reduce the lifetime of its free SSL/TLS certificates from 90 days to 64 days starting February 10, 2027, according to Ars Technica. Before that, the nonprofit certificate authority will begin testing 64-day certificates on October 14, with an opt-in option letting users try the shorter validity period on their own systems.
The change applies to the free certificates Let's Encrypt issues to websites and services, which must be renewed on a fixed schedule. Shorter lifetimes mean more frequent renewals, a process the project has long pushed toward automation.
Let's Encrypt also plans to move to 45-day default certificate lifetimes in 2028, a further step down from the 64-day period.
Why lifetimes keep shrinking
Let's Encrypt launched in early 2016 with 90-day certificates as a way to force renewal automation that did not previously exist. Before its launch, certificates were often issued for as long as one to three years.
The industry is heading toward even tighter limits: browsers will soon allow a maximum validity of 47 days for a CA-issued certificate. DigiCert has published a post explaining the schedule of certificate lifetime changes, and a talk on the current state of HTTPS was given at the NDC Toronto conference.
Quick answers
When will Let's Encrypt switch to 64-day certificates?
The 64-day lifetime starts on February 10, 2027. Testing begins on October 14, with opt-in available for users.
What happens to Let's Encrypt certificates after 2027?
Let's Encrypt plans to move to 45-day default certificate lifetimes in 2028.