Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027
Free SSL/TLS certificate lifetimes reduce to 64 days in February.

Free SSL/TLS certificate lifetimes reduce to 64 days in February.
The short version
- Let’s Encrypt is continuing a push toward tighter security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting February 10, 2027.
- For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the change should be seamless.
- For those still relying on hardcoded renewal schedules or manual processes, February will be the deadline to update before certificates start expiring unexpectedly.
What happened
Starting on October 14, Let’s Encrypt will begin testing the 64-day certificates, and interested users can opt in to test their setups before production goes live. Prior to Let’s Encrypt’s launch in early 2016 , certificates were often issued for as long as one to three years.
Why it matters
The service started with 90-day certificates to force renewal automation that didn’t previously exist.
Summary by Nerd News Network. Read the full article at Ars Technica via the links above and below.
