Technology

Let's Encrypt shortens certificate life: is your renewal ready?

Let's Encrypt is shortening the life of its free certificates. Renewal scripts on fixed schedules are at risk: what to check on your site and what to do.

Short answer

Let's Encrypt is shortening the validity period of its free SSL/TLS certificates. Sites that renew with fixed-schedule scripts or by hand are at risk, because a site whose certificate is not renewed in time shows a browser security warning. Sites whose renewal is fully automated and follows the timing the certificate authority announces should be largely unaffected.

Highlights

  • Free certificates drop from 90 days to 64 days; the change starts on 10 February 2027.
  • A test period opens on 14 October, so you can try your setup beforehand.
  • Renewal scripts with hardcoded day counts, and manual renewal, can leave certificates expiring unexpectedly after February.
A woman working on a laptop in a data centre
Photo: Christina Morillo / Pexels

2 min readAuthor: UNIT Journal EditorEditor-in-chief: Uğur Deniz İlhan

Let's Encrypt, the free certificate authority, is cutting the validity of its SSL/TLS certificates from 90 days to 64 days. The change starts on 10 February 2027, as reported by Ars Technica.

What exactly is Let's Encrypt changing?

A certificate is the digital document showing that the connection between your site and a visitor is encrypted; when it expires, browsers show a security warning. Let's Encrypt's free certificates have been valid for 90 days until now, and under the new regime they will last 64 days.

On 14 October the company opens a test period for 64-day certificates, so users can try their own setups before production goes live. The period during which a validation can be reused also falls from 30 days to 10 days and will shrink to seven hours by 2028. A 45-day default is also planned for 2028.

Who is at risk?

For people who renew through an ACME client, the software that obtains and renews certificates automatically, the move should be seamless, especially if the client supports ARI (ACME Renewal Information). ARI lets the certificate authority tell the client when to renew.

The risk lies with scripts that fix the renewal time at an interval, for example "60 days before expiry", and with manual processes. According to Ars Technica, these sites may find certificates expiring unexpectedly from February. Let's Encrypt recommends searching scripts for hardcoded numbers such as 83, 80 and 60, which were common under the 90-day regime, and updating them so renewal happens before the new limit.

What should companies and agencies in Turkey do?

The suggestions below are not in the source; they are our own assessment. An expired certificate can show visitors a security warning on an ad landing page or a shop, which on a campaign page means ad budget wasted.

  • List which domains in your hosting, CDN and server panels use Let's Encrypt.
  • Search renewal scripts for hardcoded day counts and check your ACME client's ARI support.
  • Set alerts for certificate expiry and renewal failures, including campaign subdomains.
  • Use the test period opening on 14 October to test your renewal setup.

Frequently asked

If my certificate renews automatically, do I need to do anything?
Usually not, if your ACME client supports ARI. It is still worth testing the renewal timing and failure alerts before February.

Sources

  1. Ars Technica ·

Follow UNIT Journal

What's new in search, AI and technology, in your feed every day.

Related articles

← Back to UNIT Journal

Let us measure
your visibility today.

We map your current search visibility and your standing inside generative engines. Free, one page, real data.

Request an Analysis
Get a Quote