Let’s Encrypt Slashes Certificate Lifespans and Sunsets mTLS on May 13
ID: 45c8a52e-f4af-5ff2-8c81-b1002b0fb9b6
STIX ID: report--45c8a52e-f4af-5ff2-8c81-b1002b0fb9b6
Feed Name: securityonline.info
Let’s Encrypt will deploy three ACME profile changes on May 13, 2026: (1) the tlsserver profile will issue 45-day certificates as part of a phased move to shorter lifetimes, (2) the tlsclient profile will be locked to existing accounts and is slated for deprecation on July 8, 2026 (requiring migration for mTLS users), and (3) the classic profile will begin using new “Generation Y” intermediates that chain to existing trusted roots; these changes are already available in staging and administrators should test automation against the staging API.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
