How is this reasonable? What is their threat model? Did they even consider that this directly threatens availability to those that don't automate everything? Soon certs become a blocker for backups. The 63-day old snapshot of infra is on the edge of useless in an emergency.
I don't mind 64-day certificates. However they recommended renew at 2/3 validity remaining means that I can no longer take a month off without needing to be prepared to debug a certificate re-issuance problem. Not a problem for companies with 24/7 oncall or even at most a week of the whole company off at a time. But for individuals this is pretty annoying.
Sure, re-issuance usually works. But when you only do it every 42 days it does break from time-to-time without you noticing.
I would love if we still renew with 30d remaining. I really don't care if they reduce certificate lifetime to 31 days as long as I am allowed to renew daily. But lowering the gap between expiry and when you are allowed to renew is very annoying.
Be ready because their plan is to reduce the lifetime to 7d as soon as possible for their evil masterplan to strip us off reasonable control about our websites.
Now that they have a dominant position they do Google style and Google influenced move.
You are at their will fit whatever retarded dictatorial decision they want.
Given this is a free service, what's the endgame of this "evil plan"? I don't know much about SSL and such so I assumed lowering this lifetime has some safety benefit
With a longer lifetime there are validity checks. If the life is lower than the maximum time to cache a validity check then they are unnecessary, every renewal is like its own validity check.
"Let's encrypt" was the excuse to impose "https" as mandatory and web browser and so. So let's say you have a home device, https is also mandatory to not have to go through countless warning hops.
But they said: it is ok now, because you can get a certificate for free with let's encrypt.
So suppose, you have a local device not connected to internet or your own private network server/services, with 3 month validity, it was short but you were able to generate the certificate in some way, manually, and deploy it manually also.
You could also easily manual renew and deploy the certificates.
Now, with a very short period, especially the 7 days that is their end goal, your devices needs to be constantly connected to internet, constantly receiving "things" from LE that are automatically downloaded and "installed". And it becomes impossible, to manually manage the certificate renewal, so you are force to let automatic scripts/agent do that work.
And most probably also let the script/agent auto-update itself because of "breaking changes" like it happened with certbot.
And all of that being, with a short lifetime, you are now constantly at will of Let's Encrypt, and in the end the US state and government where all of this is located. You depend of the https for a lot of things, now at the US gov will you can be cut off, eventually be monitored or be targeted, in a very short timeframe of "days" instead of months.
You can also more easily have your certificates impersonated in a hard to catch way as certificates will be constantly renewed.
And even in a non evil plot, if anything happens to let's encrypt, down time or anything, you could have your service broken with dead certificate in a so short time that you would not even have the time to look for a solution. Today you have at least months to figure out.
What about the things ACME can't automate? Word around the shop is that this is basically Apple making this change and forcing everyone else in the group to follow along
Thank you for sharing this because I utilize LetsEncrypt for my services. I especially liked the guidance on automated renewals as the expiry period is now short enough to justify automating it. I'm currently doing it manually but a cron that runs a bash script for this is plenty.
How is this reasonable? What is their threat model? Did they even consider that this directly threatens availability to those that don't automate everything? Soon certs become a blocker for backups. The 63-day old snapshot of infra is on the edge of useless in an emergency.
[dead]
I don't mind 64-day certificates. However they recommended renew at 2/3 validity remaining means that I can no longer take a month off without needing to be prepared to debug a certificate re-issuance problem. Not a problem for companies with 24/7 oncall or even at most a week of the whole company off at a time. But for individuals this is pretty annoying.
Sure, re-issuance usually works. But when you only do it every 42 days it does break from time-to-time without you noticing.
I would love if we still renew with 30d remaining. I really don't care if they reduce certificate lifetime to 31 days as long as I am allowed to renew daily. But lowering the gap between expiry and when you are allowed to renew is very annoying.
Be ready because their plan is to reduce the lifetime to 7d as soon as possible for their evil masterplan to strip us off reasonable control about our websites.
Now that they have a dominant position they do Google style and Google influenced move.
You are at their will fit whatever retarded dictatorial decision they want.
Given this is a free service, what's the endgame of this "evil plan"? I don't know much about SSL and such so I assumed lowering this lifetime has some safety benefit
With a longer lifetime there are validity checks. If the life is lower than the maximum time to cache a validity check then they are unnecessary, every renewal is like its own validity check.
"Let's encrypt" was the excuse to impose "https" as mandatory and web browser and so. So let's say you have a home device, https is also mandatory to not have to go through countless warning hops.
But they said: it is ok now, because you can get a certificate for free with let's encrypt. So suppose, you have a local device not connected to internet or your own private network server/services, with 3 month validity, it was short but you were able to generate the certificate in some way, manually, and deploy it manually also.
You could also easily manual renew and deploy the certificates.
Now, with a very short period, especially the 7 days that is their end goal, your devices needs to be constantly connected to internet, constantly receiving "things" from LE that are automatically downloaded and "installed". And it becomes impossible, to manually manage the certificate renewal, so you are force to let automatic scripts/agent do that work. And most probably also let the script/agent auto-update itself because of "breaking changes" like it happened with certbot.
And all of that being, with a short lifetime, you are now constantly at will of Let's Encrypt, and in the end the US state and government where all of this is located. You depend of the https for a lot of things, now at the US gov will you can be cut off, eventually be monitored or be targeted, in a very short timeframe of "days" instead of months.
You can also more easily have your certificates impersonated in a hard to catch way as certificates will be constantly renewed.
And even in a non evil plot, if anything happens to let's encrypt, down time or anything, you could have your service broken with dead certificate in a so short time that you would not even have the time to look for a solution. Today you have at least months to figure out.
How long until 1 hour certificate lifetimes?
https://letsencrypt.org/2025/12/02/from-90-to-45
Extrapolating linearly from the next planned decrease to 45 days in February 2028, we can expect to see 1 hour lifetimes in late 2030.
What about the things ACME can't automate? Word around the shop is that this is basically Apple making this change and forcing everyone else in the group to follow along
Thank you for sharing this because I utilize LetsEncrypt for my services. I especially liked the guidance on automated renewals as the expiry period is now short enough to justify automating it. I'm currently doing it manually but a cron that runs a bash script for this is plenty.