> The First Reduction in Their History: 64-Day Let's Encrypt Certificates
[AUTHOR: Scott Helme]
[DATE: 09/10/2026 09:38]
[LANGUAGE: EN]
I remember being in the room at DEF CON 23 in Las Vegas, in 2015, listening to "Let's Encrypt – Minting Free Certificates to Encrypt the Entire Web". It was still months before Let's Encrypt would launch their public beta and begin cementing 90-day certificates as the new norm. More than a decade later, Let's Encrypt have just announced their first ever reduction to their default certificate lifetime, and it's coming soon.The DatesHere's what's happening and when:
Date
Change
14 Oct 2026
Staging starts issuing 64-day certificates
10 Feb 2027
Production default drops from 90 days to 64 days
10 Feb 2027
Authorisation reuse drops from 30 days to 10 days
11 May 2027
The last 90-day certificate expires
16 Feb 2028
Default drops again to 45 days, authorisation reuse to 7 hours
Any certificate issued on or after 10 Feb 2027 gets a 64-day validity period, unless you've already opted in to something shorter than that. Those options have been around for a while now, with the 6-day certificates available via the shortlived profile and 45-day certificates via the tlsserver profile. What changes in February is the validity period for certificates using the default profile, so this will impact everybody, including those that may not have been paying attention.Why Now?Let's Encrypt have been ahead of the curve for their entire existence, launching with 90-day certificates when 3-year certificates were the norm, and this change is a continuation of that trend.Last year, Ballot SC-081 passed at the CA/Browser Forum, setting a schedule that takes the maximum certificate lifetime from 398 days down to 200 days (March 2026), then 100 days (March 2027), and finally 47 days in March 2029. The maximum period that domain validation data can be reused shrinks alongside it, down to just 10 days by 2029.Let's Encrypt's 90-day certificates were already comfortably inside the 2026 and 2027 changes, so they didn't have to do anything until 2029. Instead, they're stepping down gradually, with a 64-day stop on the way to 45 days, and giving everyone the ability to test this out gradually.As for why shorter is better, I've been banging this drum for a long time... Revocation is broken, and has been for as long as I've been writing about it, so the only reliable way to limit the damage of a compromised key or a mis-issued certificate is to make sure the certificate doesn't live very long. I wrote Why we need to do more to reduce certificate lifetimes back in 2018, watched Ballot SC22 fail in 2019, saw Apple force the issue with the 1-year cap in 2020, and then asked Are shorter certificates finally coming?! in 2024. They are, and this is what it looks like when they arrive.What Might BreakIf your ACME client supports ARI (ACME Renewal Information), Let's Encrypt will tell it when to renew, and you don't need to think about the lifetime of your certificates at all.ARI is relatively new though, and I'd bet, given how long Let's Encrypt have been around, that many automation processes are run on a fixed schedule. For 90-day certificates, renewing at 60 days old would be quite typical. This means that for those who have a fixed 60-day renewal process, this first reduction to 64-day certificates will just catch the new certificates before they expire, an intentional choice from Let's Encrypt I'm sure. If that is the case, organisations won't see any negative impact from this first reduction, but the 47-day certificates coming in March 2029 will cause problems and Let's Encrypt are reducing their certificates to 45-day certificates in February 2028 ahead of the deadline.What To Do NowThe best thing is to check if your ACME client supports ARI and use that wherever possible. If not, you need to check how your certificates renew and if it's a fixed schedule. If you're renewing on a fixed schedule, it ideally needs to change to be relative to the validity period of the certificate, and you should aim to renew your certificates when they're 2/3 of the way through their validity period. For your existing 90-day certificates that's at 60 days, but for these new 64-day certificates, I'd be renewing them at 42 days. After more than a decade at 90 days, the default is finally moving, and in a little less than 18 months from now, every Let's Encrypt certificate will be valid for half as long as it is today! It's pretty crazy to look back over how the ecosystem has changed during that time, and it's fair to say that Let's Encrypt has played, and continues to play, an enormous part in that.