3 min Security

Let’s Encrypt requires administrators to renew certificates

Let’s Encrypt requires administrators to renew certificates

Starting next year, websites and online services will have to renew their security certificates more frequently. Effective February 10, 2027, Let’s Encrypt is shortening the validity period of its free SSL/TLS certificates from 90 to 64 days. Organizations that still operate on fixed renewal schedules will need to adapt their systems in particular.

Ars Technica reports this. The change is part of a broader trend in which security certificates are becoming valid for increasingly shorter periods. Let’s Encrypt plans to take the next step in 2028, moving to a validity period of just 45 days. As a result, automatic certificate renewal is becoming increasingly important for the management of websites and other online services.

Shorter validity periods are intended to limit the risks associated with stolen private keys and incorrectly issued certificates. After all, if a certificate falls into the wrong hands, it can be misused throughout its validity period. By shortening that period, the potential damage is also reduced.

Fixed renewal schedules pose a risk

This change primarily affects organizations that renew certificates using scripts that include fixed timeframes. For example, a system that requests a new certificate only after 80 days still functions properly with the current 90-day validity period. Starting in February, however, the same system would be too late.

Let’s Encrypt therefore advises administrators to check their existing configurations for hard-coded timeframes. The organization specifically mentions values such as 60, 80, and 83 days, which are found in older renewal procedures. ACME clients that use ACME Renewal Information (ARI) are preferred. This allows Let’s Encrypt to notify the client directly when a certificate is due for renewal. Administrators then no longer need to set fixed intervals themselves.

For systems that do not yet support ARI, it is necessary to adapt existing renewal procedures. Let’s Encrypt recommends renewing certificates when approximately two-thirds of their validity period has elapsed. Organizations should also verify that they receive alerts if a renewal fails.

Test period begins next week

To prevent issues during the transition, Let’s Encrypt will offer the option to test certificates with a 64-day validity period starting October 14. This will allow administrators to verify that their automation is functioning correctly before the new term becomes the default in February.

At the same time, Let’s Encrypt is changing how it reuses domain validations. The period during which a previous validation remains valid will be shortened from 30 to 10 days. By 2028, that period is set to decrease further to seven hours. Among other things, the certificate authority aims to eliminate the need for repeated checks of CAA records.

Most organizations will hardly notice these changes as long as their certificate management is fully automated. For administrators who still rely on manual processes or outdated scripts, however, the margin for error is becoming increasingly narrow.

That is also the intent behind the policy. When Let’s Encrypt began issuing certificates valid for 90 days in 2016, that was already significantly shorter than the typical validity periods of one to three years at the time. The organization used that limitation to encourage automatic renewal. With this new reduction, that approach is being further implemented.