Advisory
Published 2026-10-07
Verified 2026-10-09

Let's Encrypt moves to 64-day certificates by default from 10 February 2027 (staging from 14 October 2026) and cuts authorisation reuse from 30 to 10 days; check hard-coded renewal timers now

Let's Encrypt announced on 7 October 2026 that every certificate it issues or renews on or after 10 February 2027 will be valid for 64 days by default instead of 90, unless the subscriber picks one of the shorter 45-day or roughly six-day profiles it has already announced. The last 90-day certificates should expire on 11 May 2027, and existing certificates will not be revoked. The staging environment switches to 64-day certificates on 14 October 2026 so administrators can check renewal behaviour early. Clients that support ACME Renewal Information (ARI) will be told when to renew; anything renewing at a fixed number of days before expiry should move to about two-thirds of the lifetime (around day 43), and Let's Encrypt suggests searching cron jobs, wrapper scripts and runbooks for hard-coded values such as 83, 80 or 60. The authorisation reuse period also drops from 30 days to 10 days, and to seven hours in 2028, ahead of a 2029 industry limit; rate limits, ACME endpoints and issuance chains do not change. Default lifetimes are due to fall to 45 days in February 2028. Shorter lifetimes reduce the damage from a stolen key or a mis-issued certificate. Primary: Let's Encrypt; wire: Cyber Security News.

Product
Let's Encrypt public TLS certificates (ACME)
Versions
n/a — default profile change
Exploited in Australia?
unknown
Patch to
Confirm your ACME client supports ARI, or renew at about two-thirds of lifetime; remove hard-coded 60/80/83-day timers; add alerts for failed renewals; try the staging environment from 14 Oct 2026.

Primary: Let's Encrypt — 64-day certificates (7 Oct 2026) · Cyber Security News — Let's Encrypt cuts TLS certificate lifetimes from 90 to 64 days (9 Oct 2026)

tech network