Skip to content

Let's Encrypt shortens cert lifetime to 47 days

Web Hosting by sofialund 8 replies 523 views
#1

¡News reaction: Let's Encrypt shortens cert lifetime to 47 days!

The certificate new is crazy no? ¡47 days only!

Before was 90 days, already the automation necessary was... now is the automation double necessary!

I run the server small for the clients 12, and the script bash I have... ¡will break for sure! The renewals every month and half... ¡caramba!

The ACME clients all will update? Or we need the migration to new tool? I am using the certbot old, version the 1.12...

¡tell me your plans friends!

hot air, steady hand, magic smoke
#2

Hej, no, this is big problem...

On server I have 34 certificates... into config many are the virtualhost old...

Malý script I wrote will not work... no, need rewrite...

certbot has the plugin for renewal, hej? But I am not trusting... no...

Better to test on malý VPS first... no, before touching production...

What ACME client you use? I am hearing good things about the client small written in go... no, name I forget...

boot anything, anywhere, anytime
#3

¡the certificate new is crazy no!

Or is it obviously the best thing that ever happened to our industry /s

How do you say, clearly we all needed more renewal e-mails in our lives. Obviously 47 days is plenty of time to debug why your cron job failed at 2 AM on sunday.

> The ACME clients all will update
> Or we need the migration to new tool

Or whether you should have automated properly from start. /s

No wait, that was sincere. Hard to tell, I know. I will correct myself: that was obviously sarcasm. /s

#4

I run 52 boxes so this hits different

Math time:
- 52 certs × 7.7 renewals/year = 400 renewals
- was 208 at 90 days
- my automation failure rate: ~2%
- that's 8 broken certs/year vs 4 before

Cost comparison by headache:
- manual fix: 2 hrs × $75 = $150 per incident
- new automation tool: $0 + 6 hrs setup
- switching CA: Vultr offers 60 days still, $0 — https://www.vultr.com/pricing/

Currently on certbot 2.x across fleet, mixed results. Thinking of standardizing on acme.sh or that rust client everyone's talking about.

Anyone benchmarked RAM usage? My smallest box has 512MB, 12 containers fighting for it

seedbox, NAS, tape, and three offsite
#5

This raises serious questions under eIDAS 2.0 framework and GDPR Article 32 security obligations.

Article 13 flashbacks aside, the EU Digital Identity wallet specifications may require certificate transparency logging that 47-day cycles complicate. I am drafting correspondence to my supervisory authority regarding whether accelerated renewal constitutes "appropriate technical measures" or creates availability risks.

For those processing personal data: document your ACME automation under Article 30 records. A failed renewal causing service downtime could trigger breach notification timelines if TLS termination affects data integrity controls.

I urge collective industry response to CAB Forum. This feels regulatory-adjacent.

#6

Bullet points for clarity:

- current situation: Let's Encrypt 47-day proposal, not yet enforced
- effective date: anticipated 2027 per their timeline
- preparation window: approximately 18 months remain

Personal mitigation:

- inventory all certificates by expiry automation status
- test renewal frequency under 47-day simulation
- evaluate alternative CAs: Vultr, HostHatch CA, self-hosted step-ca

Professional obligation:

- from memory Contabo's ToS has something about requiring notice for infrastructure changes affecting client services, I think it's 30 days
- I have initiated compliance review

R.R.

if it ain't broke, rust it
#7

47 days? Lol good luck with that

#8

Which certbot version are you running?

#9

Certbot 1.12 is ancient my friend, you need to upgrade that thing before 47 days hits. I was on 1.10 til last year and half my renewals failed random, not worth the headache.

$3/year. 128MB RAM. Pure happiness.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft