https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability Languages [language-i] English Catala Cestina Dansk Deutsch Greek Espanol Suomi Francais `bryt Magyar Bahasa Indonesia Italiano Ri Ben Yu hangugeo Polish Portugues do Brasil Russkii siNhl Srpski Svenska Tamil Thai Turkce Ukrayins'ka Tieng Viet Jian Ti Zhong Wen Fan Ti Zhong Wen Skip navigation links Let's Encrypt * Documentation * Get Help * Blog * Donate + Become a Sponsor + Current Sponsors & Funders + Get Involved + Donate * About Us + Let's Encrypt + Frequently Asked Questions (FAQ) + Policy and Legal Repository + Service Status + Statistics + Contact + Careers + Annual reports + Internet Security Research Group (ISRG) * Donate Now Donate Now Blog 6-day and IP Address Certificates are Generally Available By Matthew McPherrin * January 15, 2026 Short-lived and IP address certificates are now generally available from Let's Encrypt. These certificates are valid for 160 hours, just over six days. In order to get a short-lived certificate subscribers simply need to select the 'shortlived' certificate profile in their ACME client. Short-lived certificates improve security by requiring more frequent validation and reducing reliance on unreliable revocation mechanisms. If a certificate's private key is exposed or compromised, revocation has historically been the way to mitigate damage prior to the certificate's expiration. Unfortunately, revocation is an unreliable system so many relying parties continue to be vulnerable until the certificate expires, a period as long as 90 days. With short-lived certificates that vulnerability window is greatly reduced. Short-lived certificates are opt-in and we have no plan to make them the default at this time. Subscribers that have fully automated their renewal process should be able to switch to short-lived certificates easily if they wish, but we understand that not everyone is in that position and generally comfortable with this significantly shorter lifetime. We hope that over time everyone moves to automated solutions and we can demonstrate that short-lived certificates work well. Our default certificate lifetimes will be going from 90 days down to 45 days over the next few years, as previously announced. IP address certificates allow server operators to authenticate TLS connections to IP addresses rather than domain names. Let's Encrypt supports both IPv4 and IPv6. IP address certificates must be short-lived certificates, a decision we made because IP addresses are more transient than domain names, so validating more frequently is important. You can learn more about our IP address certificates and the use cases for them from our post announcing our first IP Certificate. We'd like to thank the Open Technology Fund and Sovereign Tech Agency, along with our Sponsors and Donors, for supporting the development of this work. Internet Security Research Group (ISRG) Let's Encrypt is a free, automated, and open Certificate Authority brought to you by the nonprofit Internet Security Research Group (ISRG). Read all about our nonprofit work this year in our 2025 Annual Report. Legal Address 548 Market St, PMB 77519 San Francisco, CA 94104-5401 USA Send all mail or inquiries to: PO Box 18666 Minneapolis, MN 55418-0666 USA Subscribe for email updates about Let's Encrypt and other ISRG projects (c) 2026 Internet Security Research Group * GitHub * LinkedIn * Terms * Privacy Policy * Trademark Policy