Arstechnica Let’s Encrypt Reduces TLS Certificate Lifetimes to 64 Days Starting February 2027
Article Content
- •Let’s Encrypt will shorten TLS certificate lifetimes from 90 to 64 days starting February 2027.
- •The change aims to promote automated renewal processes and enhance security.
- •Testing for the new 64-day certificates begins on October 14, 2026.
Let’s Encrypt announced a reduction in the default lifetime of its SSL/TLS certificates from 90 days to 64 days, effective February 10, 2027. This change aims to enhance security by encouraging automated renewal processes among website operators. The new policy will affect all certificates issued or renewed from that date, while shorter profiles of 45 days will also be available. The move follows Let’s Encrypt's initial introduction of 90-day certificates in 2016, which aimed to promote faster renewal and limit risks associated with key theft. Starting October 14, 2026, Let’s Encrypt will begin testing the 64-day certificates, allowing users to opt in for early testing. The shift towards shorter lifetimes is part of a broader trend to enhance web security and automate certificate management.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Common questions
What is the new certificate lifetime?
When does this change take effect?
How can I prepare for this change?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…