Emergency server help: get in touch

Let’s Encrypt Changes 2025 to 2028: What Hosting Admins Must Do

Let's Encrypt changes from 2025 to 2028: no expiry emails, no OCSP, no clientAuth EKU, Gen Y intermediates, 64- then 45-day certificates, and what cPanel and DirectAdmin admins must do.

Published 8 min read

Short answer: Let’s Encrypt stopped sending expiry emails (June 2025), removed OCSP (URLs gone May 2025, service off August 2025), dropped the TLS Client Authentication EKU (default profile February 2026, fully by July 2026) and now issues from the new “Generation Y” intermediates. Next, default certificates shrink from 90 to 64 days on 10 February 2027 and to 45 days on 16 February 2028, with domain validation reuse cut to 10 days and then 7 hours. Hosting admins need their own expiry monitoring, renewal based on lifetime or ARI rather than fixed days, and DCV that succeeds every time.

Applies to cPanel & WHM 11.138 and DirectAdmin 1.711+ (tested 1.712) on AlmaLinux 9.8

We checked the certificates and renewal settings below on our lab servers (AlmaLinux 9.8 with cPanel & WHM 11.138 and DirectAdmin 1.712) on 6 October 2026. Dates were checked against letsencrypt.org the same day.

Timeline at a glance

DateChangeStatus on 6 Oct 2026
9 Jan 2025ACME profiles available (classic, tlsserver, shortlived)Done
7 May 2025Certificates no longer contain an OCSP URL; CRL URL instead. Requests with OCSP Must-Staple failDone
4 Jun 2025Expiration notification emails turned off; account email addresses deletedDone
6 Aug 2025OCSP service shut downDone
24 Nov 2025Issuance from the new Generation Y roots and intermediates beginsDone (our lab certificates come from YR1 and YE2)
15 Jan 2026Six-day (160-hour) and IP address certificates generally availableDone
11 Feb 2026TLS Client Authentication EKU removed from the default classic profileDone
13 May 2026tlsserver profile switches to 45-day certificates (opt-in)Done
8 Jul 2026Temporary tlsclient profile retired; no more client-auth certificatesDone
10 Feb 2027Default classic profile: 64-day certificates, 10-day authorization reuseUpcoming
16 Feb 2028Default classic profile: 45-day certificates, 7-hour authorization reuseUpcoming

Let’s Encrypt says changes reach its staging environment about a month before production, and that you see a new lifetime at your first renewal after each date.

Changes that already happened

No more expiry emails

Let’s Encrypt used to warn you by email when a certificate was close to expiry. Since 4 June 2025 it does not, and it deleted the email addresses tied to ACME accounts. If a renewal silently fails, nobody tells you. Add your own monitoring: our SSL Expiry Check script checks web and mail ports from cron, and our Uptime, SSL and Blacklist Monitor sends email alerts. cPanel and DirectAdmin still send their own AutoSSL / renewal failure notices if those are enabled.

OCSP is gone, CRLs only

Current Let’s Encrypt certificates have no OCSP URL in the Authority Information Access extension, only a CRL Distribution Point. Our lab certificates showed exactly that:

$ echo | openssl s_client -connect example.com:465 -servername example.com 2>/dev/null | \
    openssl x509 -noout -issuer -startdate -enddate -ext extendedKeyUsage,crlDistributionPoints,authorityInfoAccess
issuer=C=US, O=Let's Encrypt, CN=YR1
notBefore=Oct  5 17:55:15 2026 GMT
notAfter=Jan  3 17:55:14 2027 GMT
X509v3 Extended Key Usage:
    TLS Web Server Authentication
Authority Information Access:
    CA Issuers - URI:http://yr1.i.lencr.org/
X509v3 CRL Distribution Points:
    Full Name:
      URI:http://yr1.c.lencr.org/65.crl

(Run on our cPanel lab against Exim’s port 465, hostname replaced.) What to do:

  • OCSP stapling has nothing to staple. nginx logs "ssl_stapling" ignored, no OCSP responder URL in the certificate as a warning; you can remove ssl_stapling lines for Let’s Encrypt-only servers to keep logs clean.
  • If you ever configured your ACME client to request OCSP Must-Staple, remove that option: such requests fail since 7 May 2025.
  • Firewalls that only allowed OCSP traffic to the CA need to allow the CRL host instead, if your software checks revocation.

No TLS Client Authentication EKU

The certificates above list only TLS Web Server Authentication. Websites, IMAP, POP3 and SMTP servers are not affected. What breaks is any setup that used a Let’s Encrypt certificate as a client certificate to authenticate to another server (mutual TLS between services, some replication or server-to-server links). Those need a private CA or another certificate source.

New Generation Y intermediates

Our cPanel lab’s RSA certificate was issued by YR1 and our DirectAdmin lab’s ECDSA certificate by YE2. The new roots (ISRG Root YR and YE) are cross-signed by the older X1 and X2 roots. Normal clients need no action, but anything that pins a specific intermediate, or a monitoring check that expects “R10/R11” or “E5/E6” as the issuer name, must be updated.

What is coming: 64 days, then 45 days

From 10 February 2027 the default certificate lasts 64 days, and from 16 February 2028 it lasts 45 days. At the same time the authorization reuse period, the time a successful domain validation can be reused for new certificates, drops from 30 days to 10 days and then to 7 hours. In practice almost every renewal will need a fresh HTTP or DNS validation.

Let’s Encrypt’s advice: use an ACME client with ACME Renewal Information (ARI), which tells the client when to renew; otherwise renew at about two thirds of the lifetime. A hardcoded “renew every 60 days” schedule will fail with 45-day certificates. Rate limits do not change, because renewals are exempt from the new-order limits.

You can test today: request the tlsserver profile (45-day certificates, 7-hour authorization reuse) for a few domains and watch whether renewals work.

cPanel AutoSSL

On our cPanel 11.138 lab, the Let’s Encrypt provider (cpanel-letsencrypt-v2-1.05-4.8.1) starts replacing a certificate when it has 29 days left; cPanel’s own Sectigo provider uses 15 days:

$ grep -n DAYS_TO_REPLACE /var/cpanel/perl/Cpanel/SSL/Auto/Provider/LetsEncrypt/Constants.pm /usr/local/cpanel/Cpanel/SSL/Auto/Provider/cPanel.pm
/var/cpanel/perl/Cpanel/SSL/Auto/Provider/LetsEncrypt/Constants.pm:27:    DAYS_TO_REPLACE => 29,
/usr/local/cpanel/Cpanel/SSL/Auto/Provider/cPanel.pm:33:    DAYS_TO_REPLACE => 15,

A 29-day window still works with 64-day and 45-day certificates (renewal after about 35 and 16 days). We found no ARI or profile references in that plugin version, so cPanel requests the default profile. The bigger risk is validation: with 10-day and then 7-hour reuse, a domain whose HTTP DCV fails (Cloudflare redirects, a broken .htaccess, DNS pointing elsewhere) will hit its renewal window without a valid authorization. Clean up AutoSSL failures now; our AutoSSL DCV Failures Report lists them.

DirectAdmin

DirectAdmin 1.711 changed renewal to use a fraction of the certificate lifetime instead of a fixed number of days. On our 1.712 lab:

$ /usr/local/directadmin/directadmin config | grep -E "^(acme_cert_lifetime|default_acme)"
acme_cert_lifetime_renew_jitter=0.1
acme_cert_lifetime_renew_threshold=0.65
default_acme_profile=
default_acme_provider=letsencrypt

DirectAdmin’s changelog explains that 0.65 means renewal after 65% of the lifetime (58.5 days for a 90-day certificate, 29.25 days for a 45-day one) with up to 10% random jitter. default_acme_profile lets you request a specific profile such as tlsserver; empty means the CA default. If you are still on an older DirectAdmin build, update to get the lifetime-based renewal.

Certbot, acme.sh and other clients

  • Check that your client supports ARI or renews by lifetime, and update it. Certbot added support for the six-day and IP profiles in 2026; read your client’s changelog for ARI.
  • Replace any cron job that renews on a fixed day count longer than two thirds of 45 days.
  • Reload every service that uses the certificate after renewal: web server, Exim, Dovecot, Postfix, FTP. Shorter lifetimes make a forgotten reload show up faster.

Check that it worked

  1. List certificates expiring within 20 days across your servers and confirm each one has a pending or recent renewal.
  2. Inspect a fresh certificate with the openssl command above: you should see a Y* intermediate, a CRL URL, no OCSP URL and only the server-auth EKU.
  3. Check mail ports too (465, 587 with STARTTLS, 993, 995), not just 443. Our SSL Certificate Checker shows the chain and expiry.
  4. Confirm your monitoring alerts you at least a week before expiry.

Official documentation: Let’s Encrypt: upcoming features · Let’s Encrypt: decreasing certificate lifetimes to 45 days · Let’s Encrypt: profiles · DirectAdmin 1.711 changelog

Related: 47-Day SSL Certificate Lifetime: Critical Automation for Hosts · cPanel AutoSSL Provider: Sectigo or Let’s Encrypt, Best Choice · AutoSSL Failed cPanel: Fix DCV, CAA and CDN Problems · DirectAdmin Certificate Not Renewing: Fix Failed Renewals · SSL Expiry Check Script: Free Network Test for Web and Mail

See also: ERR_CERT_COMMON_NAME_INVALID on cPanel: Wrong Certificate Served · 200-Day SSL Certificates and DCV Reuse: What It Means for AutoSSL

Frequently asked questions

Does Let’s Encrypt still send expiry emails?

No. Let’s Encrypt turned off expiration notification emails on 4 June 2025 and deleted ACME account email addresses. Use your own monitoring.

When do Let’s Encrypt certificates become 45 days?

The default classic profile moves to 64 days on 10 February 2027 and to 45 days on 16 February 2028. The opt-in tlsserver profile already issues 45-day certificates.

Do Let’s Encrypt certificates still support OCSP?

No. OCSP URLs were removed from new certificates on 7 May 2025 and the OCSP service was shut down on 6 August 2025. Revocation is published through CRLs.

Can I still use a Let’s Encrypt certificate for client authentication?

No. The TLS Client Authentication EKU was removed from the default profile on 11 February 2026 and the temporary tlsclient profile was retired on 8 July 2026.

Will shorter lifetimes hit Let’s Encrypt rate limits?

Let’s Encrypt says no change is needed, because renewals are exempt from its new-order rate limits.

Does cPanel AutoSSL handle 45-day certificates?

On our cPanel 11.138 lab the Let’s Encrypt provider renews when 29 days remain, which still leaves room with 45-day certificates. Reliable domain validation becomes the main risk.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
cPanel & WHM 11.138 and DirectAdmin 1.711+ (tested 1.712) on AlmaLinux 9.8
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.