Let's Encrypt Will Default to 64-Day Certificates on February 10, 2027, With Staging Testing From October 14
Let's Encrypt says it will issue 64-day certificates by default from February 10, 2027, shortening authorization reuse to 10 days; 45-day certificates follow in 2028.
Editor's Note ·
- Correction:
- The article says LWN.net's summary 'describes the 64-day step as an intermediate move toward 45-day certificates in 2028' and refers to LWN's 'October 9 front page'. The LWN item (posted October 9, 2026) does not use the word 'intermediate' and does not mention a front page; it says 'This is the second stage of Let's Encrypt's plan, announced in 2025, to move to 45-day certificate lifetimes' and 'In 2028, Let's Encrypt will switch to 45-day certificates.'
- Correction:
- The article says the February 24, 2026 Let's Encrypt post was retrieved through a summarizing tool, so no detail from it is quoted. The archived copy of that post contains its full text, which states that renewals are exempt from rate limits and that the default lifetime is moving from 90 days to 64 days and then 45 days. The statement about a summarizing tool was inaccurate.
- Clarification:
- The article says developers and operators who run ACME clients on fixed renewal timers are 'the group most likely to need to act'. This is the writer's inference; Let's Encrypt's October 7, 2026 post says clients that support ACME Renewal Info 'should be all set' and that renewals hard-coded to a date from expiration should be updated to about two-thirds of the lifetime, but it does not say which group is most likely to be affected.
Overview
Let’s Encrypt, the free certificate authority run by the nonprofit Internet Security Research Group, said in an October 7, 2026 blog post that on February 10, 2027 all of its subscribers will move to certificates with 64-day lifetimes by default, unless they select an even shorter lifetime of 45 or 6 days. LWN.net also reported the schedule on its October 9 front page.
The change is the first of two scheduled default reductions. Developers and operators who run ACME clients on fixed renewal timers are the group most likely to need to act.
What We Know
- Start date. According to Let’s Encrypt, any certificate it issues or renews on and after February 10, 2027 will have a 64-day validity period, and it expects the last 90-day certificate to expire on May 11, 2027.
- No revocations. The post states: “We will not revoke valid certificates as a part of this process.”
- Testing window. Let’s Encrypt says it will switch to issuing 64-day certificates in its staging environment on October 14, 2026, and recommends testing in staging before the change takes effect in production.
- Authorization reuse. The same post says the authorization reuse period will fall from 30 days to 10 days, and that in 2028 it will shrink to seven hours.
- Rate limits. Let’s Encrypt says rate limits will not be impacted by this change. An earlier February 24, 2026 post by Jacob Hoffman-Andrews addresses the same question of rate limits during the transition (the page was retrieved through a summarizing tool, so no detail from it is quoted here).
- Stated rationale. Let’s Encrypt says it is moving to shorter certificate lifetimes “because this reduces the risk of key compromise and mis-issuance.”
What Developers Are Told to Do
The October post says that if renewals are automated and the client supports ACME Renewal Info (ARI), “you should be all set” because ARI allows Let’s Encrypt to tell the client when to renew. For renewals hard-coded to a fixed interval before expiration, Let’s Encrypt says they should be updated to renew at approximately two-thirds of the certificate lifetime.
An earlier December 2, 2025 post gave related advice for the 45-day case, stating that renewing at a hardcoded interval of 60 days will no longer be sufficient, and that manually renewing certificates is not recommended because it will need to be done more frequently.
Background: The Longer Schedule
The December 2025 post, written by Matthew McPherrin, said the change is being made along with the rest of the industry, as required by the CA/Browser Forum Baseline Requirements. That post listed three dates: May 13, 2026, when the opt-in tlsserver ACME profile would switch to 45-day certificates; February 10, 2027, when the default classic ACME profile would move to 64-day certificates with a 10-day authorization reuse period; and February 16, 2028, when the classic profile would move to 45-day certificates with a 7-hour authorization reuse period.
The October 2026 post restates the February 10, 2027 date. LWN.net’s summary of the announcement describes the 64-day step as an intermediate move toward 45-day certificates in 2028.
The December post also said the organization was working with the CA/Browser Forum and the IETF on a validation method called DNS-PERSIST-01, in which the DNS TXT entry used to demonstrate control does not have to change at each renewal. It said at that time that it expected the method to be available in 2026. The sources reviewed for this article do not report whether that has happened.
What We Don’t Know
- The sources reviewed do not say how many subscribers still rely on fixed renewal timers or manual renewal.
- The October post does not restate the February 16, 2028 date for the 45-day step; that date comes from the December 2025 post, and the October post says only that the reuse period will shrink in 2028.
- Other certificate authorities’ timelines are not covered by the sources used here.
Analysis
The operational effect, as described by Let’s Encrypt, is more frequent renewals and more frequent proof of domain control. The organization’s own guidance points to ARI and to renewing at about two-thirds of the lifetime as the compatible approaches. With staging available from October 14, 2026, developers have roughly four months between the staging switch and the production date to confirm that their automation behaves correctly with 64-day certificates.