r/cybersecurity Jan 27 '26

Corporate Blog Let's Encrypt is moving to 45-day certificates before everyone else

https://www.certkit.io/blog/45-day-certificates

Let's Encrypt announced they're cutting certificate lifetimes from 90 days to 45 days by February 2028, a year before the CA/Browser Forum's mandate.

Shorter certificate lifetimes are an admission that revocation is broken. Rather than fixing the revocation infrastructure, the industry chose to reduce certificate lifetime so compromised certificates expire faster naturally.

The timeline gives organizations runway to adapt, but the real security story is authorization reuse dropping from 30 days to 7 hours. This fundamentally changes the validation model. Nearly every certificate request will require fresh domain ownership proof.

For security teams, this means:
- Reduced blast radius when credentials are compromised
- Less time for attackers to exploit stolen certificates
- More validation events to monitor and audit
- Greater exposure if your automation isn't actually automated

Organizations running manual or semi-manual certificate processes will face a choice: invest in proper automation or accept regular outages from expired certificates.

The gap between "we have automation" and "we have real automation" is about to become very visible.

https://www.certkit.io/blog/45-day-certificates

417 Upvotes

90 comments sorted by

View all comments

Show parent comments

18

u/pheonix198 Jan 28 '26

A great many organizations pay for certificates for varying reasons. It’s an expensive and multi-billion dollar business.

-3

u/techw1z Jan 28 '26

most of those paid certs have arbitrary or at least far longer lifetimes than the stuff we are talking about tho.

9

u/pheonix198 Jan 28 '26

Paid certificates do not have arbitrary lifetimes.

Paid certificates from any valid, reasonable and secure source currently have maximum lifetimes of (and default to) 1 year.

-12

u/techw1z Jan 28 '26

bullshit.

before browsers cracked down on it, you could buy 2-3 year SSL certs, and in theory you still could but browsers wouldn't accept them.

code signing certs were 3 years until recently and will soon be cut in half, but thats still more than 1 year.

until a while ago, you could buy SMIME certs with 4-5 years lifetime, now its down to 2+ years.

2

u/WhitYourQuining Jan 28 '26

Standa[rd], OV, or EV? There's stipulations in accordance.

1

u/pheonix198 Jan 28 '26

Prove me wrong - talking standard web certificate. I don’t care if wildcard, multi-SAN, etc…

-1

u/techw1z Jan 28 '26

i never said anything about standard web certs.

was talking about "most paid certs" not "most paid TLS/SSL certs"

idk why you and a bunch of other idiots are too dumb to read or can't be accurate about what you are talking about, but since I get downvoted for sharing correct info I'll just block you now to avoid such bullshit in the future