{"article":{"slug":"64-day-certificate-lifetimes-coming-feb-2027","title":"64-Day Certificate Lifetimes Coming Feb 2027","subtitle":null,"summary":"Let's Encrypt will move all subscribers to 64-day certificates by default on February 10, 2027 (with 45- and 6-day profiles available), staging first, as part of the industry shift to shorter lifetimes that reduce key-compromise and mis-issuance risk.","content_type":"announcement","language":"en","canonical_url":"https://letsencrypt.org/2026/10/07/64-day-certs.html","author":{"name":null,"url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Let's Encrypt","url":"https://letsencrypt.org/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Infrastructure","slug":"infrastructure","url":"https://listedarticles.com/topics/infrastructure"},{"name":"Web Development","slug":"web-development","url":"https://listedarticles.com/topics/web-development"}],"about_listings":[],"cover_image_url":"https://letsencrypt.org/images/LetsEncrypt-SocialShare.png","license":"all-rights-reserved","word_count":416,"reading_minutes":2,"published_at":"2026-10-07T00:00:00.000Z","added_at":"2026-10-09T05:16:30.418Z","updated_at":"2026-10-09T05:16:30.418Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/64-day-certificate-lifetimes-coming-feb-2027","markdown_url":"https://listedarticles.com/articles/64-day-certificate-lifetimes-coming-feb-2027.md","example":false,"citation":"Let's Encrypt. \"64-Day Certificate Lifetimes Coming Feb 2027.\" 7 Oct 2026. https://letsencrypt.org/2026/10/07/64-day-certs.html (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://letsencrypt.org/2026/10/07/64-day-certs.html"},"body_markdown":"On February 10, 2027, all Let’s Encrypt subscribers will move to certificates with 64 day lifetimes by default unless they [select](https://letsencrypt.org/docs/profiles/) an even shorter lifetime (45 or 6 days, as [previously announced](https://letsencrypt.org/2025/12/02/from-90-to-45)). This means that any certificate we issue or renew on and after that date will have a 64 day validity period, and we expect the last 90-day certificate to expire on May 11, 2027. We will not revoke valid certificates as a part of this process.\n\nWe will switch to issuing 64 day certificates in our [staging environment](https://letsencrypt.org/docs/staging-environment/) on October 14, 2026 to enable testing. We recommend testing in staging before the change takes effect in production.\n\nIf your renewals are automated and your client supports ACME Renewal Info (ARI), you should be all set since ARI allows Let’s Encrypt to tell your client when to renew (you can review your ACME client’s documentation to determine if ARI is implemented).\n\nIf your renewals are hard-coded to a date from expiration you should update them to renew at approximately ⅔ of the lifetime instead. Taking this step in preparation for 64 day lifetimes will lay the groundwork for default lifetimes of [45 days in 2028](https://letsencrypt.org/2025/12/02/from-90-to-45). Grep for common hardcoded numbers like 83, 80 or 60 in cron jobs, wrapper scripts and runbooks if you’re not sure.\n\nWe will also be reducing the authorization reuse period from 30 days to 10 days. In 2028, the reuse period will shrink to seven hours. We are making this change to comply with a 2029 reduction in maximum validation reuse periods, and to remove the need for “CAA rechecking”, where we have to repeat part of the validation process if the validation data is more than 7 hours old. Unless you have specifically designed your ACME client to rely on validation reuse, you will not need to make any changes.\n\nThis is also an opportunity to automate certificate management processes like reload and deployment and to add alerting for renewal failures.\n\nRate limits will not be impacted by this change; you can learn more in our previous [blog post](https://letsencrypt.org/2026/02/24/rate-limits-45-day-certs).\n\nThis change will not affect ACME endpoints or our issuance chains.\n\nWe are moving to shorter certificate lifetimes because this reduces the risk of key compromise and mis-issuance. As a nonprofit we see it as part of our mission to make this change to advance security for everyone using the Web globally. We anticipate a smooth transition, but if you experience issues, our [community forum](https://community.letsencrypt.org/) and [documentation](https://letsencrypt.org/docs/) are good resources.","body_html":"<p>On February 10, 2027, all Let’s Encrypt subscribers will move to certificates with 64 day lifetimes by default unless they <a href=\"https://letsencrypt.org/docs/profiles/\" rel=\"nofollow ugc noopener\">select</a> an even shorter lifetime (45 or 6 days, as <a href=\"https://letsencrypt.org/2025/12/02/from-90-to-45\" rel=\"nofollow ugc noopener\">previously announced</a>). This means that any certificate we issue or renew on and after that date will have a 64 day validity period, and we expect the last 90-day certificate to expire on May 11, 2027. We will not revoke valid certificates as a part of this process.</p>\n<p>We will switch to issuing 64 day certificates in our <a href=\"https://letsencrypt.org/docs/staging-environment/\" rel=\"nofollow ugc noopener\">staging environment</a> on October 14, 2026 to enable testing. We recommend testing in staging before the change takes effect in production.</p>\n<p>If your renewals are automated and your client supports ACME Renewal Info (ARI), you should be all set since ARI allows Let’s Encrypt to tell your client when to renew (you can review your ACME client’s documentation to determine if ARI is implemented).</p>\n<p>If your renewals are hard-coded to a date from expiration you should update them to renew at approximately ⅔ of the lifetime instead. Taking this step in preparation for 64 day lifetimes will lay the groundwork for default lifetimes of <a href=\"https://letsencrypt.org/2025/12/02/from-90-to-45\" rel=\"nofollow ugc noopener\">45 days in 2028</a>. Grep for common hardcoded numbers like 83, 80 or 60 in cron jobs, wrapper scripts and runbooks if you’re not sure.</p>\n<p>We will also be reducing the authorization reuse period from 30 days to 10 days. In 2028, the reuse period will shrink to seven hours. We are making this change to comply with a 2029 reduction in maximum validation reuse periods, and to remove the need for “CAA rechecking”, where we have to repeat part of the validation process if the validation data is more than 7 hours old. Unless you have specifically designed your ACME client to rely on validation reuse, you will not need to make any changes.</p>\n<p>This is also an opportunity to automate certificate management processes like reload and deployment and to add alerting for renewal failures.</p>\n<p>Rate limits will not be impacted by this change; you can learn more in our previous <a href=\"https://letsencrypt.org/2026/02/24/rate-limits-45-day-certs\" rel=\"nofollow ugc noopener\">blog post</a>.</p>\n<p>This change will not affect ACME endpoints or our issuance chains.</p>\n<p>We are moving to shorter certificate lifetimes because this reduces the risk of key compromise and mis-issuance. As a nonprofit we see it as part of our mission to make this change to advance security for everyone using the Web globally. We anticipate a smooth transition, but if you experience issues, our <a href=\"https://community.letsencrypt.org/\" rel=\"nofollow ugc noopener\">community forum</a> and <a href=\"https://letsencrypt.org/docs/\" rel=\"nofollow ugc noopener\">documentation</a> are good resources.</p>","headings":[]}}