2025-04-14
CA/Browser Forum Votes to Cut Certificate Lifespan to 47 Days
Members of the Certificate Authority/Browser Forum have voted to shorten the lifespan of SLS/TLS certificates to just under seven weeks. The changes will roll out gradually over the next several years until March 2029, when certificate lifetimes will be limited to 47 days. While the organization has argued that shortening the duration of the certificates' viability will improve security, others point out that the entities issuing the certificates will benefit financially from the changes. While no members of the CA/Browser Forum voted against the move, five members abstained from voting.
Editor's Note
This change has been in the works for a while, and some proposals asked for even shorter certificate lifetimes. Automation is key to keeping certificates valid, and tools like the EFF 'certbot' will make it easier to adapt. The latest version of certbot, 4.0, allows users to select different certificate profiles. Currently, two are supported. The default profile uses standard 90-day certificates. An alternative short-lived profile reduces the certificate validity time to 6 days.

Johannes Ullrich
Looks like the CA/Browser Forum is continuing to finally move forward on making the use of SSL certificates more meaningful to actual security of web traffic. Even with long lifetimes many organizations had problems knowing where certs were in use and when they would expire. Use of certificate management tools will become more critical as cert lifetimes shrink from over 1 year to less than two months. On the CA side, competition from multiple CAs with largely commodity certs should limit cost per year increases.

John Pescatore
On March 15, 2026, the maximum lifecycle will be 200 days, requiring six-month renewals, and on March 15, 2027, it shrinks to 100 days, requiring 90 day renewals. Finally on March 15, 2029, the interval shrinks to 47 days, with an expected monthly renewal. At this point the move is to automate all SSL/TLS certificate renewals. Find servers and appliances you're not currently automating certificate management for and work with your suppliers for solutions while you have a bit of time; March 2026 isn't that far out for making changes to business and other high stability services. Find out the certificate interval where you have automation; you may be surprised how rapidly you already are updating certificates.

Lee Neely
Read more in
Computerworld: Vendors vote to radically slash website certificate duration
BleepingComputer: SSL/TLS certificate lifespans reduced to 47 days by 2029
GitHub: cabforum / servercert