Anime, manga, and games, with a take · A Yukimedia publication

← all stories other 1 sources · 49m ago ·

Let's Encrypt Will Cut Certificate Validity To 64 Days In February 2027

The staged shortening gives administrators a test window in October 2026, but any setup that renews on a fixed schedule rather than through an ACME client with renewal notifications has roughly a year to fix its scripts before certificates start expiring early.

Reporting from 1 source: GIGAZINE.

Let's Encrypt Will Cut Certificate Validity To 64 Days In February 2027

Let's Encrypt will shorten its SSL/TLS certificate validity period from 90 days to 64 days starting February 10, 2027. Testing of the shortened certificates begins October 14, 2026, and administrators can join before production deployment. A further cut to 45 days is set for February 16, 2028. Renewal timing values such as 60 and 80 days will need adjusting, and the reuse window for authentication results drops from 30 days to 10 days.

Let's Encrypt will cut its certificate validity period from 90 days to 64 days on February 10, 2027, with a further reduction to 45 days planned for February 16, 2028. Testing of the 64-day certificates starts October 14, 2026, so administrators can try the shorter window in their own environments before it reaches production.

The change follows the CA/Browser Forum's push to shorten certificate lifetimes. Let's Encrypt recommends moving renewal timing values such as 60 and 80 days to match the new period, checking whether the ACME client supports renewal notifications, and confirming that expiration alerts are configured. Authentication results will also be reusable for 10 days instead of 30, with a further cut planned in 2028.

Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources