Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027

Let’s Encrypt is continuing a push toward tighter security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting February 10, 2027. For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the change should be seamless. For those still relying on hardcoded renewal schedules or manual processes, February will be the deadline to update before certificates start expiring unexpectedly.

Let’s Encrypt 正在通过将免费 SSL/TLS 证书的有效期从 90 天缩短至 64 天来进一步加强安全性,该政策将于 2027 年 2 月 10 日起生效。对于已经部署了支持 ARI(ACME 更新信息)的现代 ACME 客户端的管理员来说,这一变化应该是无缝衔接的。而对于那些仍然依赖硬编码更新计划或手动流程的用户来说,2 月份将是他们在证书意外过期前进行更新的最后期限。

Starting on October 14, Let’s Encrypt will begin testing the 64-day certificates, and interested users can opt in to test their setups before production goes live. Prior to Let’s Encrypt’s launch in early 2016, certificates were often issued for as long as one to three years. The service started with 90-day certificates to force renewal automation that didn’t previously exist.

从 10 月 14 日开始,Let’s Encrypt 将启动 64 天证书的测试,感兴趣的用户可以选择加入,以便在正式生产环境上线前测试其配置。在 Let’s Encrypt 于 2016 年初推出之前,证书的签发有效期通常长达一到三年。该服务最初采用 90 天证书,旨在强制推行当时尚不存在的自动化更新机制。

Shorter certificate validity periods limited vulnerabilities from private key thefts and encouraged accelerated HTTPS adoption across the web. This move shook industry norms at the time, but by limiting the certificate lifetime, the certs are less likely to cause damage if compromised or assigned in error. The move down to 64 days continues this logic, and the lifespans will only continue to get shorter as time goes on, with 45-day defaults planned to follow in 2028.

较短的证书有效期限制了私钥被盗带来的漏洞,并促进了 HTTPS 在网络上的加速普及。此举在当时撼动了行业规范,但通过限制证书寿命,即使证书被泄露或错误分配,其造成的损害也会降低。缩短至 64 天的举措延续了这一逻辑,随着时间的推移,有效期将继续缩短,计划在 2028 年将默认有效期降至 45 天。

Just as the initial rollout of Let’s Encrypt aimed to push users toward HTTPS, the shortened certificate windows are aimed at moving users to full ACME automation. The ACME protocol, and, more specifically, ARI (ACME Renewal Information), allows the certificate authority to tell the client when it’s time to renew. Although ARI does this, many deployments are still stuck on scripted update intervals that trigger at fixed offsets like “60 days before expiration.”

正如 Let’s Encrypt 最初的推出旨在推动用户转向 HTTPS 一样,缩短证书有效期旨在促使用户实现全面的 ACME 自动化。ACME 协议,特别是 ARI(ACME 更新信息),允许证书颁发机构告知客户端何时进行更新。尽管 ARI 具备此功能,但许多部署仍停留在脚本化的更新间隔上,这些脚本在“过期前 60 天”等固定时间点触发。

Let’s Encrypt is getting this information out now to warn these users to audit their cron jobs and runbooks to automatically renew at two-thirds their lifespan and, in doing so, prepare for the additional shrinkage of 45-day certificates planned for 2028.

Let’s Encrypt 现在发布此信息,旨在提醒这些用户审查其 cron 任务和运行手册,以便在证书生命周期的三分之二处自动更新,从而为 2028 年计划实施的 45 天证书进一步缩短做好准备。

What web administrators can do now: The company specifically recommends users search for hardcoded renewal numbers like 83, 80, and 60 (common previous renewal targets for 90-day certificates) and update them to renew prior to expiration at the new 64-day limit. Verify your ACME client supports ARI; if not, update renewal scripts. Ensure notifications are set in the event of certificate expiration or renewal failures. Take advantage of the October 14 testing period before the official rollout.

网站管理员现在可以做什么:该公司特别建议用户搜索硬编码的更新数字,如 83、80 和 60(此前 90 天证书的常见更新目标),并将其更新为在新的 64 天限制内于过期前进行更新。验证您的 ACME 客户端是否支持 ARI;如果不支持,请更新更新脚本。确保在证书过期或更新失败时设置了通知。在正式发布前,利用 10 月 14 日的测试期进行测试。

Alongside certificate lifetimes, Let’s Encrypt is also compressing validation timelines. Authorization reuse periods will shrink from 30 days to 10 days, and eventually to seven hours by 2028. This step should eliminate the need for CAA rechecks. Most operators won’t notice the change unless their ACME clients depend on cached validation data. Administrators will have about four months to test their renewal automations before the February 10 deadline, or risk downtime when the deadline arrives.

除了证书有效期外,Let’s Encrypt 还在压缩验证时间线。授权重用期将从 30 天缩短至 10 天,并最终在 2028 年缩短至 7 小时。此举应能消除对 CAA 重新检查的需求。除非 ACME 客户端依赖缓存的验证数据,否则大多数运营商不会注意到这一变化。管理员将有大约四个月的时间在 2 月 10 日截止日期前测试其更新自动化,否则在截止日期到来时将面临停机风险。