Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027
Summary
Let's Encrypt, a widely used certificate authority, will be shortening the lifespan of its SSL/TLS certificates. Starting in February 2027, these certificates will be valid for only 64 days, a significant reduction from the current 90-day period.
IFF Assessment
FRIEND
This change by Let's Encrypt is intended to improve security by ensuring certificates are renewed and validated more frequently, reducing the window of opportunity for compromised certificates to be exploited.
Defender Context
Defenders should be aware of this upcoming change in certificate lifetimes, as it will require more frequent automated renewal processes. Shorter lifespans mean that any misconfiguration or failure in certificate management could lead to website outages or security warnings more rapidly.