ESPNOffseason questions for eliminated teams: What's next for the Yankees?ESPN DeportesMLB Playoffs 2026: así llegan Brewers y Dodgers a la NLCSInquirerVoltage fluctuations hit Ilocos Norte amid low power delivery from NGCPDaily MaverickGROUNDUP: Ekurhuleni police force employed convicted killers, Parliament toldZDF heuteEntdecken Sie das ZDF-NachrichtenstudioABC NewsHurricane Isaias latest: Storm strengthens to Category 2Mexico News DailyPuerto Vallarta, San Miguel de Allende rank among world’s 5 best small cities in Condé Nast Traveler readers’ pollABC News (Australia)Pentagon says firing squad execution of Fort Hood shooter will be livestreamedThe Jerusalem PostShin Bet uncovers Bedouin terror cell plotting attacks on police station, Beersheba bus stationSBS 뉴스"이화영에 굽신굽신"…"한동훈 자료 유출 조사해야"Radio-CanadaPacific Link : les Premières Nations de Cold Lake saisissent la courSDP Espectáculos¿A qué hora termina Miami Horror en Foro Puebla? Horario del 8 de octubre
The Daily Newsstand · Free, Always
Thursday, October 8, 2026

Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027

Translate

Let’s Encrypt is continuing a push toward tighter security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting on February 10, 2027. For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the change should be seamless. For those still relying on hardcoded renewal schedules or manual processes, next February will be the deadline to update before certificates start expiring unexpectedly.

Starting on October 14, 2026, Let’s Encrypt will begin testing the 64-day certificates, and interested users can opt-in to test their setups before production goes live.

Prior to Let’s Encrypt’s launch in early 2016, certificates were often issued for as long as one to three years. The service started with 90-day certificates to force renewal automation that didn’t previously exist. Shorter certificate validity periods limited vulnerabilities from private key thefts and encouraged accelerated HTTPS adoption across the web.

This move was a bit of a shakeup to industry norms at the time, but by limiting the certificate lifetime, the certs are less likely to cause damage if compromised or assigned in error. The move down to 64 days continues this logic, and the lifespans will only continue to get shorter as time goes on, with 45-day defaults planned to follow in 2028.

Just as the initial rollout of Let’s Encrypt aimed to push users toward HTTPS, the shortened certificate windows are aimed at moving users to full ACME automation. The ACME protocol, and, more specifically, ARI (ACME Renewal Information), allows the certificate authority to tell the client when it’s time to renew. Although ARI does this, many deployments are still stuck on scripted update intervals that trigger at fixed offsets like “60 days before expiration.”

View the original on Ars Technica →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.