SSL/TLS Certificate - Lifespan reduction for TLS certificates
The CA/Browser (CA/B) Forum ballot has endorsed to reduce the maximum validity term of SSL/TLS certificates to 47 days by 2029.
For those manually renewing certificates, we highly recommend Automated Certificate Management Environment (ACME) protocol.
It simplifies and automates the process of issuing, renewing, and revoking SSL/TLS certificates. Utilizing ACME is a recommended method for efficient certificate life-cycle management, minimizing human error and preventing certificate expiration.
- SSL/TLS Server Certificates - Let's Encrypt Certificate Automation
- SSL/TLS Certificate - Automatically Issue and Renew InCommon with ACME
The approved measure will gradually reduce certificate lifespans from the current 398 days through a phased approach:
March 15, 2026: The maximum lifespan for many certificates will be reduced to 200 days.
March 15, 2027: Further reduction to 100 days.
March 15, 2029: The maximum lifespan will be reduced to 47 days.
Questions? Contact servercertificates@doit.wisc.edu
