Let's Encrypt shortens TLS certificate validity to 64 days in 2027
Let's Encrypt announced that, from 10 February 2027, it will issue TLS certificates valid for 64 days, with the last 90-day certificate expiring on 11 May 2027. The change is the second step of a plan toward 45 days in 2028.
Let's Encrypt, a nonprofit that provides free TLS certificates to millions of websites, announced that it will issue certificates valid for 64 days starting 10 February 2027. According to the announcement, every certificate issued or renewed from that date will be valid for 64 days, and the last 90-day certificate is expected to expire on 11 May 2027. The organization said it will not revoke valid certificates as part of this process.
The change is the second step of a plan announced in 2025 to move to 45-day certificates, as required by the CA/Browser Forum Baseline Requirements. In 2028, Let's Encrypt will begin issuing 45-day certificates. The source is an automatic translation of content published in the LWN feed, which points to the original article for verification.
For those who run sites or services that depend on TLS, the relevant point is the renewal frequency, which is likely to increase. Check the expiration dates of certificates in use and confirm that automatic renewal works before February 2027.