100-day certificates from March 2027: find the ones you renew by hand
Updated 2026-10-10 ยท by Hieu Tran, written with AI agents and checked against the sources below
Public TLS certificates issued from 15 March 2027 can last at most 100 days, and from 15 March 2029 at most 47 days (CA/Browser Forum ballot SC-081v3). Let's Encrypt moves its default to 64 days on 10 February 2027. Certificates renewed by an ACME client won't notice. The ones someone buys, downloads and installs by hand will need doing three to four times as often.
Enter a domain; your browser reads public Certificate Transparency logs and builds the list and a calendar file. Nothing goes through our servers.
The dates
Now (since 15 March 2026): 200 days maximum.
14 October 2026: Let's Encrypt staging issues 64-day certificates (test your clients now).
10 February 2027: Let's Encrypt default becomes 64 days; authorization reuse drops from 30 to 10 days.
15 March 2027: 100 days maximum for every public CA.
15 March 2029: 47 days maximum.
Step 1: list every public certificate you have
Every publicly trusted certificate is published in Certificate Transparency logs. Search your domain on crt.sh or SSLMate's Cert Spotter and you'll see the ones you've forgotten too: VPN gateways, mail servers, phone systems, old marketing sites.
Step 2: separate automated from manual
Short lifetimes (90 days or less) from Let's Encrypt, ZeroSSL or Google Trust Services almost always mean an ACME client renews them.
Cloud-issued certificates (Amazon, Google, Azure, Cloudflare) are renewed by the platform.
Long lifetimes from commercial CAs (DigiCert, Sectigo, GlobalSign, GoDaddy, Entrust) are usually bought and installed by hand. These are the ones to plan for. Some CAs do offer ACME with longer certificates, so confirm with whoever installs them.
Step 3: automate what you can, calendar the rest
Web servers: certbot or acme.sh on Linux, win-acme or Posh-ACME on Windows/IIS. Most commercial CAs offer ACME with External Account Binding (EAB).
Appliances: check your firmware. F5 BIG-IP 21.1 added native ACME (HTTP-01 only); NetScaler Console supports ACME with DNS-01; Cisco Expressway has ACME; PAN-OS uses SCEP rather than ACME.
Exchange and IIS bindings: after renewal, check the certificate is bound to the right sites and services (SMTP, IIS). A renewal that isn't bound is still an outage.
Everything still manual: put each renewal on a shared calendar, 14 days before expiry, with an owner. Let's Encrypt stopped sending expiry emails in 2025, so don't count on the CA to remind you.