Let's Encrypt: 64-Day Certificate Lifetimes By Default Coming Feb 2027
throw0101c
14 points
9 comments
October 09, 2026
Related Discussions
Found 5 related stories in 91.6ms across 8,999 title embeddings via pgvector HNSW
- Let's Encrypt: 64-Day Certificate Lifetimes Coming Feb 2027 allddd · 48 pts · October 08, 2026 · 96% similar
- ICANN Reveals 2026 Round Applications for New Generic Top-Level Domains ChrisArchitect · 33 pts · October 07, 2026 · 44% similar
- France's Anssi Will Block PQC-Free Products from Certification Starting 2027 Sami_Lehtinen · 92 pts · July 21, 2026 · 43% similar
- I've factored the RSA keys of a Certificate Authority from the 90s ahlCVA · 232 pts · September 08, 2026 · 43% similar
- Hackers obtain counterfeit TLS certificates for Google and other large services colinprince · 13 pts · October 07, 2026 · 42% similar
Discussion Highlights (5 comments)
mmmlinux
How long until 1 hour certificate lifetimes?
kittikitti
Thank you for sharing this because I utilize LetsEncrypt for my services. I especially liked the guidance on automated renewals as the expiry period is now short enough to justify automating it. I'm currently doing it manually but a cron that runs a bash script for this is plenty.
kevincox
I don't mind 64-day certificates. However they recommended renew at 2/3 validity remaining means that I can no longer take a month off without needing to be prepared to debug a certificate re-issuance problem. Not a problem for companies with 24/7 oncall or even at most a week of the whole company off at a time. But for individuals this is pretty annoying. Sure, re-issuance usually works. But when you only do it every 42 days it does break from time-to-time without you noticing. I would love if we still renew with 30d remaining. I really don't care if they reduce certificate lifetime to 31 days as long as I am allowed to renew daily. But lowering the gap between expiry and when you are allowed to renew is very annoying.
1970-01-01
How is this reasonable? What is their threat model? Did they even consider that this directly threatens availability to those that don't automate everything? Soon certs become a blocker for backups. The 63-day old snapshot of infra is on the edge of useless in an emergency.
Avicebron
What about the things ACME can't automate? Word around the shop is that this is basically Apple making this change and forcing everyone else in the group to follow along