# Let’s Encrypt Changes 2025 to 2028: What Hosting Admins Must Do

Source: https://srvscripts.com/guides/lets-encrypt-2026-changes/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** Let’s Encrypt stopped sending expiry emails (June 2025), removed OCSP (URLs gone May 2025, service off August 2025), dropped the TLS Client Authentication EKU (default profile February 2026, fully by July 2026) and now issues from the new “Generation Y” intermediates. Next, default certificates shrink from 90 to 64 days on 10 February 2027 and to 45 days on 16 February 2028, with domain validation reuse cut to 10 days and then 7 hours. Hosting admins need their own expiry monitoring, renewal based on lifetime or ARI rather than fixed days, and DCV that succeeds every time.

We checked the certificates and renewal settings below on our lab servers (AlmaLinux 9.8 with cPanel & WHM 11.138 and DirectAdmin 1.712) on 6 October 2026. Dates were checked against letsencrypt.org the same day.

## Timeline at a glance

| Date | Change | Status on 6 Oct 2026 |
| --- | --- | --- |
| 9 Jan 2025 | ACME profiles available (classic, tlsserver, shortlived) | Done |
| 7 May 2025 | Certificates no longer contain an OCSP URL; CRL URL instead. Requests with OCSP Must-Staple fail | Done |
| 4 Jun 2025 | Expiration notification emails turned off; account email addresses deleted | Done |
| 6 Aug 2025 | OCSP service shut down | Done |
| 24 Nov 2025 | Issuance from the new Generation Y roots and intermediates begins | Done (our lab certificates come from YR1 and YE2) |
| 15 Jan 2026 | Six-day (160-hour) and IP address certificates generally available | Done |
| 11 Feb 2026 | TLS Client Authentication EKU removed from the default classic profile | Done |
| 13 May 2026 | tlsserver profile switches to 45-day certificates (opt-in) | Done |
| 8 Jul 2026 | Temporary tlsclient profile retired; no more client-auth certificates | Done |
| 10 Feb 2027 | Default classic profile: 64-day certificates, 10-day authorization reuse | Upcoming |
| 16 Feb 2028 | Default classic profile: 45-day certificates, 7-hour authorization reuse | Upcoming |

Let’s Encrypt says changes reach its staging environment about a month before production, and that you see a new lifetime at your first renewal after each date.

## Changes that already happened

### No more expiry emails

Let’s Encrypt used to warn you by email when a certificate was close to expiry. Since 4 June 2025 it does not, and it deleted the email addresses tied to ACME accounts. If a renewal silently fails, nobody tells you. Add your own monitoring: our [SSL Expiry Check script](/scripts/ssl-expiry-check/) checks web and mail ports from cron, and our [Uptime, SSL and Blacklist Monitor](/tools/uptime-ssl-blacklist-monitor/) sends email alerts. cPanel and DirectAdmin still send their own AutoSSL / renewal failure notices if those are enabled.

### OCSP is gone, CRLs only

Current Let’s Encrypt certificates have no OCSP URL in the Authority Information Access extension, only a CRL Distribution Point. Our lab certificates showed exactly that:

```
$ echo | openssl s_client -connect example.com:465 -servername example.com 2>/dev/null | \
    openssl x509 -noout -issuer -startdate -enddate -ext extendedKeyUsage,crlDistributionPoints,authorityInfoAccess
issuer=C=US, O=Let's Encrypt, CN=YR1
notBefore=Oct  5 17:55:15 2026 GMT
notAfter=Jan  3 17:55:14 2027 GMT
X509v3 Extended Key Usage:
    TLS Web Server Authentication
Authority Information Access:
    CA Issuers - URI:http://yr1.i.lencr.org/
X509v3 CRL Distribution Points:
    Full Name:
      URI:http://yr1.c.lencr.org/65.crl
```

(Run on our cPanel lab against Exim’s port 465, hostname replaced.) What to do:

- OCSP stapling has nothing to staple. nginx logs `"ssl_stapling" ignored, no OCSP responder URL in the certificate` as a warning; you can remove `ssl_stapling` lines for Let’s Encrypt-only servers to keep logs clean.

- If you ever configured your ACME client to request OCSP Must-Staple, remove that option: such requests fail since 7 May 2025.

- Firewalls that only allowed OCSP traffic to the CA need to allow the CRL host instead, if your software checks revocation.

### No TLS Client Authentication EKU

The certificates above list only `TLS Web Server Authentication`. Websites, IMAP, POP3 and SMTP servers are not affected. What breaks is any setup that used a Let’s Encrypt certificate as a client certificate to authenticate to another server (mutual TLS between services, some replication or server-to-server links). Those need a private CA or another certificate source.

### New Generation Y intermediates

Our cPanel lab’s RSA certificate was issued by `YR1` and our DirectAdmin lab’s ECDSA certificate by `YE2`. The new roots (ISRG Root YR and YE) are cross-signed by the older X1 and X2 roots. Normal clients need no action, but anything that pins a specific intermediate, or a monitoring check that expects “R10/R11” or “E5/E6” as the issuer name, must be updated.

## What is coming: 64 days, then 45 days

From 10 February 2027 the default certificate lasts 64 days, and from 16 February 2028 it lasts 45 days. At the same time the **authorization reuse period**, the time a successful domain validation can be reused for new certificates, drops from 30 days to 10 days and then to 7 hours. In practice almost every renewal will need a fresh HTTP or DNS validation.

Let’s Encrypt’s advice: use an ACME client with ACME Renewal Information (ARI), which tells the client when to renew; otherwise renew at about two thirds of the lifetime. A hardcoded “renew every 60 days” schedule will fail with 45-day certificates. Rate limits do not change, because renewals are exempt from the new-order limits.

You can test today: request the `tlsserver` profile (45-day certificates, 7-hour authorization reuse) for a few domains and watch whether renewals work.

## cPanel AutoSSL

On our cPanel 11.138 lab, the Let’s Encrypt provider (`cpanel-letsencrypt-v2-1.05-4.8.1`) starts replacing a certificate when it has 29 days left; cPanel’s own Sectigo provider uses 15 days:

```
$ grep -n DAYS_TO_REPLACE /var/cpanel/perl/Cpanel/SSL/Auto/Provider/LetsEncrypt/Constants.pm /usr/local/cpanel/Cpanel/SSL/Auto/Provider/cPanel.pm
/var/cpanel/perl/Cpanel/SSL/Auto/Provider/LetsEncrypt/Constants.pm:27:    DAYS_TO_REPLACE => 29,
/usr/local/cpanel/Cpanel/SSL/Auto/Provider/cPanel.pm:33:    DAYS_TO_REPLACE => 15,
```

A 29-day window still works with 64-day and 45-day certificates (renewal after about 35 and 16 days). We found no ARI or profile references in that plugin version, so cPanel requests the default profile. The bigger risk is validation: with 10-day and then 7-hour reuse, a domain whose HTTP DCV fails (Cloudflare redirects, a broken `.htaccess`, DNS pointing elsewhere) will hit its renewal window without a valid authorization. Clean up AutoSSL failures now; our [AutoSSL DCV Failures Report](/scripts/autossl-failure-report/) lists them.

## DirectAdmin

DirectAdmin 1.711 changed renewal to use a fraction of the certificate lifetime instead of a fixed number of days. On our 1.712 lab:

```
$ /usr/local/directadmin/directadmin config | grep -E "^(acme_cert_lifetime|default_acme)"
acme_cert_lifetime_renew_jitter=0.1
acme_cert_lifetime_renew_threshold=0.65
default_acme_profile=
default_acme_provider=letsencrypt
```

DirectAdmin’s changelog explains that 0.65 means renewal after 65% of the lifetime (58.5 days for a 90-day certificate, 29.25 days for a 45-day one) with up to 10% random jitter. `default_acme_profile` lets you request a specific profile such as `tlsserver`; empty means the CA default. If you are still on an older DirectAdmin build, update to get the lifetime-based renewal.

## Certbot, acme.sh and other clients

- Check that your client supports ARI or renews by lifetime, and update it. Certbot added support for the six-day and IP profiles in 2026; read your client’s changelog for ARI.

- Replace any cron job that renews on a fixed day count longer than two thirds of 45 days.

- Reload every service that uses the certificate after renewal: web server, Exim, Dovecot, Postfix, FTP. Shorter lifetimes make a forgotten reload show up faster.

## Check that it worked

- List certificates expiring within 20 days across your servers and confirm each one has a pending or recent renewal.

- Inspect a fresh certificate with the `openssl` command above: you should see a `Y*` intermediate, a CRL URL, no OCSP URL and only the server-auth EKU.

- Check mail ports too (465, 587 with STARTTLS, 993, 995), not just 443. Our [SSL Certificate Checker](/tools/ssl-certificate-checker/) shows the chain and expiry.

- Confirm your monitoring alerts you at least a week before expiry.

**Official documentation:** [Let’s Encrypt: upcoming features](https://letsencrypt.org/upcoming-features/) · [Let’s Encrypt: decreasing certificate lifetimes to 45 days](https://letsencrypt.org/2025/12/02/from-90-to-45) · [Let’s Encrypt: profiles](https://letsencrypt.org/docs/profiles/) · [DirectAdmin 1.711 changelog](https://docs.directadmin.com/changelog/version-1.711.html)

**Related:** [47-Day SSL Certificate Lifetime: Critical Automation for Hosts](/guides/47-day-ssl-certificate-lifetime/) · [cPanel AutoSSL Provider: Sectigo or Let’s Encrypt, Best Choice](/guides/cpanel-autossl-provider-lets-encrypt/) · [AutoSSL Failed cPanel: Fix DCV, CAA and CDN Problems](/guides/autossl-failed-cpanel-dcv-caa-cdn/) · [DirectAdmin Certificate Not Renewing: Fix Failed Renewals](/guides/directadmin-certificate-not-renewing/) · [SSL Expiry Check Script: Free Network Test for Web and Mail](/scripts/ssl-expiry-check/)

**See also:** [ERR_CERT_COMMON_NAME_INVALID on cPanel: Wrong Certificate Served](/guides/cpanel-err-cert-common-name-invalid/) · [200-Day SSL Certificates and DCV Reuse: What It Means for AutoSSL](/guides/ssl-200-day-dcv-reuse/)

## Frequently asked questions

### Does Let’s Encrypt still send expiry emails?

No. Let’s Encrypt turned off expiration notification emails on 4 June 2025 and deleted ACME account email addresses. Use your own monitoring.

### When do Let’s Encrypt certificates become 45 days?

The default classic profile moves to 64 days on 10 February 2027 and to 45 days on 16 February 2028. The opt-in tlsserver profile already issues 45-day certificates.

### Do Let’s Encrypt certificates still support OCSP?

No. OCSP URLs were removed from new certificates on 7 May 2025 and the OCSP service was shut down on 6 August 2025. Revocation is published through CRLs.

### Can I still use a Let’s Encrypt certificate for client authentication?

No. The TLS Client Authentication EKU was removed from the default profile on 11 February 2026 and the temporary tlsclient profile was retired on 8 July 2026.

### Will shorter lifetimes hit Let’s Encrypt rate limits?

Let’s Encrypt says no change is needed, because renewals are exempt from its new-order rate limits.

### Does cPanel AutoSSL handle 45-day certificates?

On our cPanel 11.138 lab the Let’s Encrypt provider renews when 29 days remain, which still leaves room with 45-day certificates. Reliable domain validation becomes the main risk.
