Skip to content
Rota Nacional

Cyber ·

Let's Encrypt will issue 64-day certificates by default from February 10, 2027

Let's Encrypt will issue and renew certificates valid for 64 days starting February 10, 2027, and recommends testing automated renewal on its staging environment from October 14, 2026.

From February 10, 2027, all Let's Encrypt subscribers will receive certificates valid for 64 days by default, unless they choose a shorter validity (45 or 6 days, announced earlier). Certificates issued or renewed on or after that date will last 64 days, and the last 90-day certificate is expected to expire on May 11, 2027. The authority states it will not revoke valid certificates because of this change. 64-day issuance reaches the staging environment on October 14, 2026, for testing. Clients with automated renewal that support ACME Renewal Info (ARI) should be ready, since the server tells the client when to renew. Renewals scheduled for a fixed date should be adjusted to occur at roughly two-thirds of the validity period. The source also advises searching code for hard-coded numbers such as 83, 80 or 60 in cron jobs, scripts and procedures. The authorization reuse period drops from 30 to 10 days and, in 2028, to seven hours, to meet a reduction planned for 2029 and to remove CAA rechecking. According to the source, no changes are needed unless a client was specifically designed to rely on validation reuse. Rate limits and ACME endpoints are not affected. The stated reason is reducing the risk of key compromise and misissuance. For questions, the source points to the community forum and documentation. This text is an automatic translation of feed content; to verify dates and details, consult the original Let's Encrypt announcement published October 7, 2026, at the address given in the source.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free