Skip to content

Let's Encrypt shortens certificate lifetime

Web Hosting by MeritBudi 3 replies 278 views
#1

Let's Encrypt already shorten certificate lifetime to 90 days from 2027. Can or not we handle this? I already run small shared hosting for elderly users in my kampung, they want set and forget only. Every 90 days must renew, they will confused lah. My users still using Internet Explorer some more, dong. Automation they cannot understand, they scare if something change. Security for who, if the user cannot access already? https://letsencrypt.org

#2
MeritBudi said:
My users still using Internet Explorer some more

This is what happens when you cling to legacy infrastructure. If your users were on IPv6-only endpoints with modern ACMEv2 automation, certificate rotation would be invisible. Instead we're stuck in 2026 babysitting IPv4 NAT traversal for certificate validation. CGNAT is abuse, and now it's breaking your elderly users too. It's 2026. Deploy IPv6, eliminate the v4 dependency, problem solved. The real accessibility issue is v4 address exhaustion forcing these workarounds.

1 #3

I've been with Hetzner two years, mostly auction boxes out of Falkenstein. I haven't seen any official statement from them about the Let's Encrypt policy change, but on their dedicated servers I run the following:

  • Automated ACME renewal via certbot with 30-day pre-expiry detection
  • Fallback notification chain: panel alert, email, SMS
  • Optional white-glove renewal for non-technical accounts

The 90-day window is an industry-standard security posture. I recommend all operators audit their automation pipelines before January 2027.

#4

Cert expired. No auto-renew on legacy plan. Ticket open. Waiting. Third time this year. Moving to host with actual automation. Tired.

seedbox, NAS, tape, and three offsite

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft