Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027
摘要
Let's Encrypt 宣布自2027年2月10日起,将免费SSL/TLS证书有效期从90天缩短至64天。已使用支持ARI的现代ACME客户端的管理员可平稳过渡,仍依赖固定续期计划或手动流程的用户需在明年冬季前完成调整。2026年10月14日起将开始测试64天证书,用户可选择提前验证配置。该机构自2016年起采用90天证书以推动自动化续期,缩短有效期有助
Let's Encrypt is continuing a push toward improved security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting on February 10, 2027. For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the change should be seamless. For those still relying on hardcoded renewal schedules or manual processes, next winter will be the deadline to update before certificates start expiring unexpectedly.
Starting on October 14, 2026, Let's Encrypt will begin testing the 64-day certificates, and interested users can opt-in to test their setups before production goes live.
Prior to Let's Encrypt's launch in early 2016, certificates were often issued for as long as 1 to 3 years at a time. The service start with 90-day certificates to force renewal automation that didn't previously exist. Shorter certificate validity periods limited vulnerabilities from private key thefts and accelerated HTTPS adoption across the web.
转载信息
评论 (0)
暂无评论,来留下第一条评论吧