Cyber Security News

Let’s Encrypt Unveils New “Generation Y” Root and 45-Day Certificates

Let’s Encrypt, the nonprofit certificate authority powering free TLS/SSL certificates for millions of websites, announced sweeping updates to its issuance policies.

The changes introduce a new “Generation Y” root hierarchy, deprecate TLS client authentication, and progressively shorten certificate lifetimes to align with CA/Browser Forum requirements.

To ensure a smooth transition, Let’s Encrypt leverages ACME profiles, giving users control over rollout timing. For most, no immediate action is needed.

Central to the update is the “Generation Y” hierarchy: two new Root CAs and six Intermediate CAs, cross-signed by the existing “Generation X” roots (X1 and X2).

This maintains broad trust compatibility. The new intermediates omit the TLS Client Authentication Extended Key Usage (EKU), addressing an upcoming root program mandate. Let’s Encrypt previously detailed plans to end TLS Client Auth support from February 2026.

Profile-specific timelines vary. Users on the default classic profile switch to Generation Y on May 13, 2026. Those needing legacy TLS client auth can stick with the tlsclient profile, which remains on Generation X until May 2026.

Meanwhile, TLS server and short-lived profiles shift to Generation Y this week, enabling opt-in short-lived certificates with IP address support. This marks general availability for short-lived certs, aiding automated renewals and reducing exposure windows.

Shortening lifetimes complies with evolving CA/Browser Forum Baseline Requirements. Next year, early adopters will test 45-day certificates via tlsserver. Defaults drop to 64 days in 2027, then 45 days in 2028, as detailed in Let’s Encrypt’s lifetime reduction post.

Timeline Overview

ChangeProfile AffectedDate
Gen Y rollout (tlsserver/shortlived)tlsserver, shortlivedThis week
TLS Client Auth endAll (tlsclient legacy)Feb 2026
Gen Y default switchClassicMay 13, 2026
45-day opt-intlsserver2026
Default 64 daysAll2027
Default 45 daysAll2028

These updates strengthen security by minimizing key compromise risks through shorter validity and refined EKUs, without disrupting most workflows. Let’s Encrypt urges reviewing linked posts and community forums for edge cases, like IP certificates .

As support on Let’s Encrypt grows, securing over 300 million domains, these changes underscore proactive adaptation to industry standards, potentially influencing broader PKI ecosystems.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago