Skip to content

Commit 74444fe

Browse files
authored
Documentation about certificate lifetimes and rationale, 2nd try (#2276)
Opening a new PR since I messed up PR #1993
1 parent 30499fd commit 74444fe

34 files changed

Lines changed: 311 additions & 0 deletions
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
title: Certificate Lifetime Rationale and Plans
3+
slug: cert-lifetimes
4+
date: 2026-07-22
5+
lastmod: 2026-07-22
6+
show_lastmod: false
7+
untranslated: 1
8+
---
9+

content/ca/docs/cert-lifetimes.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
title: Certificate Lifetime Rationale and Plans
3+
slug: cert-lifetimes
4+
date: 2026-07-22
5+
lastmod: 2026-07-22
6+
show_lastmod: false
7+
untranslated: 1
8+
---
9+

content/cs/docs/cert-lifetimes.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
title: Certificate Lifetime Rationale and Plans
3+
slug: cert-lifetimes
4+
date: 2026-07-22
5+
lastmod: 2026-07-22
6+
show_lastmod: false
7+
untranslated: 1
8+
---
9+

content/da/docs/cert-lifetimes.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
title: Certificate Lifetime Rationale and Plans
3+
slug: cert-lifetimes
4+
date: 2026-07-22
5+
lastmod: 2026-07-22
6+
show_lastmod: false
7+
untranslated: 1
8+
---
9+

content/de/docs/cert-lifetimes.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
title: Certificate Lifetime Rationale and Plans
3+
slug: cert-lifetimes
4+
date: 2026-07-22
5+
lastmod: 2026-07-22
6+
show_lastmod: false
7+
untranslated: 1
8+
---
9+

content/el/docs/cert-lifetimes.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
title: Certificate Lifetime Rationale and Plans
3+
slug: cert-lifetimes
4+
date: 2026-07-22
5+
lastmod: 2026-07-22
6+
show_lastmod: false
7+
untranslated: 1
8+
---
9+

content/en/docs/cert-lifetimes.md

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
---
2+
title: Certificate Lifetime Rationale and Plans
3+
slug: cert-lifetimes
4+
lastmod: 2026-07-22
5+
show_lastmod: 1
6+
---
7+
8+
## Current Lifetimes
9+
10+
Since our initial launch in 2015, Let's Encrypt has offered certificates with 90-day lifetimes. This remains the default lifetime, and the vast majority of the certificates we issue have 90-day lifetimes.
11+
12+
Short-lived certificates with 6-day lifetimes are optionally available to all of our subscribers.
13+
14+
See our [certificate profiles documentation](/docs/profiles/) for more information.
15+
16+
## Future Plans
17+
18+
[Industry rules](https://cabforum.org/working-groups/server/baseline-requirements/documents/) will limit certificate lifetimes to a maximum of 47 days starting on March 15, 2029. As such, we will be [reducing the maximum lifetime of our certificates to 45 days by February 2028](/2025/12/02/from-90-to-45.html).
19+
20+
## Why shorter lifetimes?
21+
22+
We're sometimes asked why we only offer certificates with 90-day lifetimes, or why we're introducing even shorter lifetimes.
23+
24+
There are two primary advantages to shorter certificate lifetimes:
25+
26+
* They limit damage from mis-issuance and key compromise. Mis-issued certificates, and certificates with keys compromised either before or after issuance, are valid for a shorter period of time.
27+
* They encourage automation, which is absolutely essential for ease-of-use and reliability. Once certificate management is automated, shorter lifetimes aren't any less convenient than longer ones.
28+
29+
We chose 90-day lifetimes for our initial offering because ninety days was short enough to strongly encourage automation, but long enough to make it possible to do things manually. While we wanted to encourage automation, that goal was subordinate to making it possible for everyone to enable HTTPS. At the time, automation wasn't as common as it is today, in part because the ecosystem of tools to enable it (e.g. ACME clients) was young. Today things are very different - automation is far more common and the ecosystem of tools to enable it is much more mature. As such, we are more comfortable with offerings shorter than ninety days now than we were then.

content/en/post/2015-11-9-why-90-days.markdown

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,8 @@ title: Why ninety-day lifetimes for certificates?
88
slug: why-90-days
99
---
1010

11+
> This is a historic blog post at this point. Please see our [certificate lifetime documentation](/docs/cert-lifetimes) for the current status of certificate lifetimes.
12+
1113
We’re sometimes asked why we only offer certificates with ninety-day lifetimes. People who ask this are usually concerned that ninety days is too short and wish we would offer certificates lasting a year or more, like some other CAs do.
1214

1315
Ninety days is nothing new on the Web. According to Firefox Telemetry, 29% of TLS transactions use ninety-day certificates. That’s more than any other lifetime. From our perspective, there are two primary advantages to such short certificate lifetimes:

content/es/docs/cert-lifetimes.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
title: Certificate Lifetime Rationale and Plans
3+
slug: cert-lifetimes
4+
date: 2026-07-22
5+
lastmod: 2026-07-22
6+
show_lastmod: false
7+
untranslated: 1
8+
---
9+

content/fa/docs/cert-lifetimes.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
title: Certificate Lifetime Rationale and Plans
3+
slug: cert-lifetimes
4+
date: 2026-07-22
5+
lastmod: 2026-07-22
6+
show_lastmod: false
7+
untranslated: 1
8+
---
9+

0 commit comments

Comments
 (0)