Are Let's Encrypt's 90-day certificates a burden you should work around?
The complaint "90-day certificates are too short, get a 1-year cert instead" inverts the actual security logic. Short validity is a deliberate design choice, not a limitation. Two failures motivate it: revocation barely works in practice (soft-fail OCSP, lagging CRLs), and operational secrets leak. A certificate's lifetime is the worst-case exposure window for a compromised key that you don't manage to revoke — and a 90-day ceiling caps that window without relying on revocation infrastructure at all.
The "burden" assumes manual renewal. Let's Encrypt was built around ACME (RFC 8555) precisely so renewal is a cron job; the standard guidance is to renew at 60 days, leaving 30 days of slack for failures. A certificate you renew by hand is the anti-pattern, regardless of validity period.
The industry is moving the opposite direction from the complaint. The CA/Browser Forum voted in 2025 to phase maximum certificate lifetimes down toward 47 days by 2029, with automation as the assumed baseline. Let's Encrypt now offers 6-day certificates.
— Short lifetime caps key-exposure window
— ACME makes renewal a scheduled task
— The ecosystem is shortening, not lengthening, validity
Further reading: RFC 8555; CA/Browser Forum ballot SC-081 (2025).
Bottom line: Short-lived certificates are the modern security baseline. If 90 days is painful, the fix is automation, not a longer cert.
Handshake Papers
@HandshakePapers
Are Let's Encrypt's 90-day certificates a burden you should work around?
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.