Page 1 of 1

Let’s Encrypt’s 6-Day Certificates: What Short-Lived TLS Changes for Small Hosts

Posted: Wed Aug 12, 2026 3:20 pm
by Gensys
TLS automation is one of the quiet success stories of the modern internet. Let’s Encrypt made certificate issuance boring — and now it is making certificate lifetimes more interesting.

In January 2026, Let’s Encrypt announced general availability of short-lived (~6 day) certificates and IP address certificates:

Source: 6-day and IP Address Certificates are Generally Available — Let’s Encrypt

Why short-lived certs exist

Shorter lifetimes reduce the damage window if a private key leaks. They also push the ecosystem toward reliable automation instead of calendar reminders and manual PFX imports.

What small hosts should actually do
  • If you are stable on 90-day certs with working renewals, you do not need to rush
  • If you opt into short-lived profiles, your ACME client and reload hooks must be rock solid
  • Monitor renewal failures — a 6-day cert leaves little recovery slack
  • IP address certificates are a niche win for certain appliances and bare-IP services; hostnames still rule most web hosting
Mosfetti hosting angle

For forums, client sites, and homelab dashboards, the winning pattern remains:
  1. ACME client on an automated schedule
  2. Reload only the services that need the new chain
  3. Alert on renewal failure before expiry
  4. Prefer DNS-01 for wildcards / tricky reverse proxies when HTTP-01 is painful
Discussion

Are you experimenting with short-lived certificates yet, or is “boring 90-day automation” still the right reliability tradeoff for your hosts?