Public TLS certificates drop to a 100-day maximum on 15 March 2027 and 47 days in 2029. Let's Encrypt moves to 64 days on 10 February 2027. ACME automates web servers; load balancers, firewalls, IIS bindings and appliances are still renewed by hand. See which of yours those are, and get each renewal onto a calendar before it becomes an outage.
We'll email you about early access, at most twice. No spam; reply STOP to opt out.
Guide: 100-day certificates from March 2027: find the ones you renew by hand
Every public certificate for your domain from Certificate Transparency logs, with issuer, lifetime and expiry. No agent, no login.
Long-lived certificates from commercial CAs are usually bought and installed by hand. Those are the ones 100-day lifetimes will hit.
Every renewal date for those certificates under the new limits, as a calendar file, and alerts before each one.
“Automated certificate renewal is maybe supported by 10% of services I operate where I work.” (public Hacker News comment, Mar 2026)
“The certificate must be renewed manually and the time of validity is getting shorter.” (public TrueNAS forum post, May 2026)
Had this happen recently? Tell us what happened (4 questions, about 10 minutes, no sign-up).
MSPs: $299/month across clients. The forecast and alerts for up to 10 certificates stay free.
We'll email you about early access, at most twice. No spam; reply STOP to opt out.