Let’s Encrypt Unveils new “Generation Y” root and to 45 day certificates
ID: 3d72f4f8-39e1-5ba7-958e-92afde0c5021
STIX ID: report--3d72f4f8-39e1-5ba7-958e-92afde0c5021
Feed Name: cybersecurityNews.com
**Executive Summary:** Let's Encrypt announced a Generation Y root and intermediate CA hierarchy (cross-signed by the existing Generation X roots), the planned deprecation of TLS client authentication, and a phased reduction in certificate lifetimes—introducing short-lived certificates with IP support now and scheduling 45-day and 64-day defaults across 2026–2028—with profile-specific rollout dates and an option to remain on the legacy tlsclient profile until February 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
