Let's Encrypt Introduces Shorter-Lived TLS Certificate Profiles With New Renewal Rules
Let's Encrypt now offers two new certificate profiles alongside its default 90-day classic option: the 'tlsserver' profile valid for 45 days, and the 'shortlived' profile valid for just six days, the latter also supporting IP addresses. The classic profile itself is set to shrink to 64 days in February 2027 and then to 45 days in February 2028, leaving roughly six months for operators to begin testing their systems. Shorter certificate lifetimes make fully automated renewal essential, as manual processes are no longer practical, especially for six-day certificates. Let's Encrypt recommends migrating to ACME clients that support ACME Renewal Information (ARI), a now-official RFC standard that lets the certificate authority guide renewal timing and reduce rate-limit issues. Shopify has already published a case study showing how adopting ARI streamlined certificate renewals across millions of domains.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in