Let’s Encrypt will shorten its default TLS certificate lifetime from 90 days to 64 days on February 10, 2027, with staging tests beginning October 14, 2026. Subscribers can also select 45-day or six-day lifetimes, and existing valid certificates will not be revoked during the transition. The shorter lifetimes aim to limit exposure from compromised keys and incorrectly issued certificates. Authorization reuse will fall from 30 days to 10 days, then to seven hours in 2028, when Let’s Encrypt also plans to introduce 45-day default certificate lifetimes. Rate limits, ACME endpoints and issuance chains will remain unchanged.
Organizations relying on manual renewals or fixed schedules need to update their processes to prevent certificate expirations and service outages; Let’s Encrypt recommends renewing approximately two-thirds of the way through a certificate’s lifetime. Modern ACME clients supporting ACME Renewal Information (ARI) should accommodate the change automatically by following CA-provided renewal windows. Let’s Encrypt’s ARI integration guidance also provides a rate-limit exemption for qualifying renewals submitted within the suggested window and identifying the certificate being replaced. Administrators should verify client support, test renewal workflows in staging and check that renewal scheduling does not assume a 90-day lifetime.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
Let’s Encrypt contributed follow-up pull request 2114 to Lego to support changes in draft-ietf-acme-ari-03.
Let’s Encrypt contributed follow-up pull request 2066 to Lego to support changes in draft-ietf-acme-ari-02.
Let’s Encrypt contributed a pull request to the Lego ACME client to support draft-ietf-acme-ari-01.
Let’s Encrypt enabled ACME Renewal Information (ARI) in its staging and production environments, allowing clients to obtain certificate renewal guidance from the certificate authority.
Let’s Encrypt launched in early 2016 with 90-day certificates to encourage automated renewal and HTTPS adoption.
Let’s Encrypt announced plans for a 64-day default certificate lifetime beginning February 10, 2027, with staging testing scheduled for October 14, 2026, and no revocation of existing valid certificates. The plan also includes a 45-day default in 2028 and reductions in authorization reuse from 30 days to 10 days, then seven hours in 2028.
Let’s Encrypt published a technical guide covering ARI discovery, renewal scheduling, certificate identification, and replacement orders. It announced that qualifying ARI renewals are exempt from all rate limits when submitted within the suggested renewal window and identifying the certificate being replaced.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
7 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcearstechnica.com
Open sourceletsencrypt.org
Open sourceletsencrypt.org
Open sourceletsencrypt.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.