Cert Renewal ForecastGuide

Let's Encrypt goes to 64 days on 10 February 2027: what to check now

Updated 2026-10-11 ยท by Hieu Tran, written with AI agents and checked against the sources below

Let's Encrypt announced on 7 October 2026 that all certificates will be 64 days by default from 10 February 2027, down from 90, and that authorization reuse drops from 30 to 10 days. Staging starts issuing 64-day certificates on 14 October 2026. A well-configured ACME client won't notice. What breaks is everything around it.

Free tool: Free renewal forecast: your public certificates, the manual ones, and a 2027 renewal calendar

Enter a domain; your browser reads public Certificate Transparency logs and builds the list and a calendar file. Nothing goes through our servers.

The dates

Checklist

  1. Does your client support ARI (ACME Renewal Information)? Then Let's Encrypt tells it when to renew, and the shorter lifetime is handled for you.
  2. Search for hard-coded renewal days. Let's Encrypt suggests grepping cron jobs, wrapper scripts and runbooks for values like 83, 80 or 60. A script that renews 60 days after issue will let a 64-day certificate expire within four days of the renewal attempt. Renew at about two-thirds of the lifetime instead.
  3. Check the reload. A renewed certificate on disk does nothing until the service reloads. Make the deploy hook reload nginx, Apache, HAProxy or the mail server, and check it actually fires.
  4. Alert on renewal failures, not just on expiry. Let's Encrypt stopped sending expiry emails in 2025.
  5. Clients that relied on 30-day authorization reuse (validating once, then issuing many orders) need to validate more often. Let's Encrypt says most clients don't depend on it.

The certificates that ACME renews but a person installs

The common gap: certbot renews on a Linux box, then someone copies the files to a firewall, NAS, printer, VPN gateway or load balancer. At 90 days that copy was four times a year; at 64 days it's about every six weeks, and at 45 days eight times a year. List every place a Let's Encrypt certificate ends up, and either automate the copy (the device's API, its own ACME client) or put each copy on a calendar with an owner.

Certificates from commercial CAs (DigiCert, Sectigo, GlobalSign and others) don't follow Let's Encrypt's dates, but they are capped at 100 days from 15 March 2027 anyway, so the hand-installed ones get the same treatment a few weeks later.

Free tool: Free renewal forecast: your public certificates, the manual ones, and a 2027 renewal calendar

Enter a domain; your browser reads public Certificate Transparency logs and builds the list and a calendar file. Nothing goes through our servers.

Which of your Let's Encrypt certificates get copied somewhere by hand after renewal (an appliance, a NAS, a load balancer), and how did you find out last time it was missed?

We're researching this problem and read every answer. Tell us what happened (4 short questions, no sign-up; AI tools help us read the answers).

More guides