Let's Encrypt shortens certificate validity to 45 days starting May 2026

I have no support/technical question and have seen the support category. (Be aware that direct support questions will be deleted.)

on

Which general topic do you have

For those users, who manually renew Letsencrypt certificates:

https://www.heise.de/en/news/Web-PKI-Let-s-Encrypt-shortens-certificate-validity-to-45-days-11100410.html

If you manually need to open port 80 for renewing the certificate(s), you will have more work in the future.
If you renew the certificate via cronjob, you will need a shorter interval, depending on:

It starts on May 13, 2026: Anyone who wishes can order certificates with a validity of 45 days from that day onwards, and must use the optional certificate profile “tlsserver” for this. On February 10, 2027, the validity for all newly issued certificates will then initially drop to 64 days, and a little over a year later, on February 16, 2028, to 45 days.

1 Like

The first activity from Google had the target of 10 days.

That would make a manually renew nearly impossible.

1 Like