Follow the latest coverage, related explainers and connected technology stories.
Let’s Encrypt will reduce the validity period of free SSL/TLS certificates from 90 to 64 days starting February 10, 2027, with an optional test beginning October 14, 2026. System administrators will need to automate renewal and support ACME and ARI to avoid certificate expiration and website outages.
Attackers exploited control of the .gh, .sl, and .as domains to modify DNS records and pass automated validation processes, then obtain unauthorized TLS certificates for domains belonging to Google and other global brands. Chrome blocked the certificates identified by Google, but the company warned that browser-level intervention does not protect all users or guarantee the detection of every certificate.