Let's Encrypt now offers 6-day (160-hour) short-lived certificates and IP address certificates as generally available features. Short-lived certificates enhance security by reducing the vulnerability window from 90 days to just over 6 days when private keys are compromised, addressing the unreliability of traditional revocation mechanisms. These certificates are opt-in and require selecting the 'shortlived' profile in ACME clients. IP address certificates support both IPv4 and IPv6 authentication and must use the short-lived format due to the transient nature of IP addresses. Standard certificate lifetimes will transition from 90 to 45 days over the coming years.

2m read timeFrom letsencrypt.org
Post cover image
178 Impressions