Published 2026-09-30 · Updated 2026-09-30
Let's Encrypt Is Moving to 45-Day Certificates: What Changes for Your Renewal Automation
Let's Encrypt is phasing out its familiar 90-day certificate lifetime in favor of much shorter options, and the change is not optional in the long run. Six-day certificates became generally available in January 2026 as an opt-in profile. The tlsserver profile switched to 45-day certificates on May 13, 2026 for early adopters. The default classic profile, the one almost every automated renewal setup actually uses, moves to 64-day certificates with a 10-day authorization reuse period on February 10, 2027, and then to 45-day certificates on February 16, 2028. None of this requires action today for most operators, but it is worth understanding now, before a renewal assumption baked into old automation quietly turns into an expired certificate.
In this article
The timeline, in full Why shorter certificate lifetimes What actually breaks ACME Renewal Information: the fix DNS-PERSIST-01, for DNS-based validation What to check on your own server Frequently asked questionsQuick win (10 minutes)
- Check your ACME client and version: certbot, acme.sh, or another client, and confirm it is a recent release that supports ACME Renewal Information (ARI).
- Search any custom renewal scripts, cron jobs, or systemd timers for a hardcoded interval, such as a comment or variable referencing "60 days" or "every two months".
- Confirm your renewal process actually checks the certificate's real expiry rather than assuming a fixed calendar schedule:
openssl x509 -enddate -noout -in /path/to/cert.pem. - If you use DNS-based validation, check whether your DNS provider or ACME client already supports or plans to support DNS-PERSIST-01.
The timeline, in full
According to Let's Encrypt's own announcement, the transition happens in stages rather than all at once. Six-day, IP-address-capable certificates reached general availability in January 2026 as an opt-in "shortlived" profile for early adopters and specialized use cases. On May 13, 2026, the "tlsserver" ACME profile began issuing 45-day certificates, also opt-in. The bigger change for most sites lands on February 10, 2027, when the default "classic" profile, the one issued when a certificate request specifies no particular profile, switches to 64-day certificates with a 10-day authorization reuse period. A further reduction to 45-day certificates on the classic profile, with a 7-hour authorization reuse period, is scheduled for February 16, 2028.
| Date | Change |
|---|---|
| January 2026 | 6-day "shortlived" profile, opt-in, generally available |
| May 13, 2026 | "tlsserver" profile switches to 45-day certificates, opt-in |
| February 10, 2027 | Default "classic" profile switches to 64-day certificates |
| February 16, 2028 | Default "classic" profile switches to 45-day certificates |
Why shorter certificate lifetimes
A shorter-lived certificate limits how long a compromised private key stays useful to an attacker, since the certificate itself expires and is reissued long before a 90-day or longer window would have closed that exposure. It also reduces how much the entire public certificate ecosystem depends on revocation, a mechanism that has historically been slow to propagate and inconsistently checked by browsers and clients in practice; a certificate that simply expires in days needs no revocation check to stop being trusted. This direction is not unique to Let's Encrypt. The CA/Browser Forum's Ballot SC-081v3 sets an industry-wide phased schedule reducing the maximum validity of any publicly trusted TLS certificate to 200 days in 2026, 100 days in 2027, and 47 days in 2029, which every public certificate authority, not only Let's Encrypt, will eventually have to follow.
What actually breaks
According to Let's Encrypt's own guidance, most sites that already automatically issue and renew certificates through a standard ACME client will not need to change anything, because a well-built ACME client renews based on the certificate's actual remaining validity, not a hardcoded interval. What breaks is any automation, custom script, monitoring check, or documentation that assumes a fixed renewal cadence, such as "renew every 60 days" or a cron job scheduled explicitly around a 90-day cycle. Under 45-day or 6-day certificates, that kind of hardcoded assumption produces an expired certificate and a real outage, not a late but still successful renewal. This is the same category of risk our patch management guide covers for OS updates: automation that quietly assumes a stable interval breaks the moment that interval changes underneath it, and the failure is invisible until it causes an outage.
Not sure your renewal automation would survive shorter certificates?
A free, read-only server check reviews TLS configuration and certificate expiry without making any changes.
Get your free server check Talk to a security engineerACME Renewal Information: the fix
ACME Renewal Information, or ARI, is Let's Encrypt's answer to the hardcoded-interval problem. Instead of a client guessing when to renew based on a fixed number of days, ARI lets the client ask the certificate authority directly, through the ACME protocol itself, when a given certificate should be renewed. According to Let's Encrypt's ARI announcement, this removes the need for any client-side assumption about certificate lifetime entirely, which is exactly the property that keeps renewal automation working correctly as lifetimes shorten across multiple profile changes over the next several years. Confirming that your ACME client supports ARI, most current versions of certbot and other major clients already do, is the single most durable fix available.
DNS-PERSIST-01, for DNS-based validation
Sites that validate domain ownership through DNS TXT records, rather than through an HTTP challenge, face a specific operational cost from shorter certificate lifetimes: more frequent renewals mean more frequent DNS updates, unless the validation method itself changes. Let's Encrypt has been developing DNS-PERSIST-01 specifically to address this, allowing a DNS TXT record to be set up once and reused across renewals rather than updated every time, which materially reduces the operational burden of frequent validation for sites using DNS-based challenges under a shorter-lifetime future.
What to check on your own server
- Confirm your ACME client is current and supports ARI, rather than relying on a fixed renewal schedule.
- Search custom scripts, monitoring checks, and internal documentation for any hardcoded assumption about certificate lifetime measured in a specific number of days.
- If you use DNS-based validation, track DNS-PERSIST-01 support in your client and provider rather than assuming your current setup scales to more frequent renewals indefinitely.
- None of this requires urgent action for a typical small business VPS today, since the default profile most sites use does not change until February 2027 at the earliest, but auditing renewal automation now costs little and avoids a scramble later.
For the broader picture of how TLS configuration fits into overall server hardening, see our nginx security best practices guide, which covers TLS configuration alongside security headers and rate limiting.
Frequently asked questions
What is Let's Encrypt changing about certificate lifetimes?
Let's Encrypt is phasing out its 90-day default certificate lifetime in stages. Six-day certificates became generally available in January 2026 as an opt-in profile. The tlsserver profile switched to 45-day certificates on May 13, 2026 for early adopters. The default classic profile moves to 64-day certificates with a 10-day authorization reuse period on February 10, 2027, then to 45-day certificates on February 16, 2028.
Why is Let's Encrypt shortening certificate lifetimes?
Shorter-lived certificates reduce the window during which a compromised private key remains usable and lessen reliance on revocation systems, which have historically been slow and inconsistently checked by clients. The change also follows the CA/Browser Forum's Ballot SC-081v3, which sets an industry-wide phased reduction of maximum public TLS certificate validity to 200 days in 2026, 100 days in 2027, and 47 days in 2029.
Do I need to change anything right now?
Most users who already automatically issue and renew certificates through a standard ACME client will not need to make changes immediately, since the shorter lifetimes roll out as opt-in profiles before becoming the default. The one thing worth checking now is whether any renewal automation assumes a fixed interval, such as renewing exactly every 60 or 90 days, rather than renewing based on the certificate's actual remaining validity.
What is ACME Renewal Information (ARI)?
ARI is a mechanism that lets an ACME client ask the certificate authority directly when it should renew a given certificate, rather than relying on a hardcoded assumption about certificate lifetime. Let's Encrypt recommends ACME clients support ARI specifically because hardcoded renewal intervals will produce outages once certificates with materially shorter lifetimes become the default.
What is DNS-PERSIST-01?
DNS-PERSIST-01 is a domain validation method Let's Encrypt has been developing that allows a persistent DNS TXT record to be set up once, rather than updated on every renewal, reducing the operational burden of frequent domain validation under shorter certificate lifetimes for sites that use DNS-based validation.
Does this affect self-signed or internally issued certificates?
No. This change is specific to publicly trusted certificates issued by Let's Encrypt and follows an industry-wide CA/Browser Forum policy that governs publicly trusted certificate authorities generally. Internal certificate authorities used for private infrastructure are not bound by this schedule, though adopting shorter lifetimes voluntarily is good practice regardless.
Not sure where your server stands?
Get a free, read-only security check, or talk to a security engineer about managed protection.
Get your free server check Talk to a security engineer