{"id":9308,"date":"2025-12-18T10:03:49","date_gmt":"2025-12-18T10:03:49","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/18\/lets-encrypt-unveils-new-generation-y-root-and-45-day-certificates\/"},"modified":"2025-12-18T10:03:49","modified_gmt":"2025-12-18T10:03:49","slug":"lets-encrypt-unveils-new-generation-y-root-and-45-day-certificates","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/18\/lets-encrypt-unveils-new-generation-y-root-and-45-day-certificates\/","title":{"rendered":"Let\u2019s Encrypt Unveils New \u201cGeneration Y\u201d Root and 45-Day Certificates"},"content":{"rendered":"<p>    Let\u2019s Encrypt Unveils New \u201cGeneration Y\u201d Root and 45-Day Certificates<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Let\u2019s Encrypt, the nonprofit certificate authority powering free TLS\/SSL certificates for millions of websites, announced sweeping updates to its issuance policies.<\/p>\n<p>The changes introduce a new \u201cGeneration Y\u201d root hierarchy, deprecate TLS client authentication, and progressively shorten certificate lifetimes to align with CA\/Browser Forum requirements.<\/p>\n<p>To ensure a smooth transition, Let\u2019s Encrypt leverages <a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-45-days-certificate\/\" target=\"_blank\" rel=\"noreferrer noopener\">ACME profiles<\/a>, giving users control over rollout timing. For most, no immediate action is needed.<\/p>\n<p>Central to the update is the \u201cGeneration Y\u201d hierarchy: two new Root CAs and six Intermediate CAs, cross-signed by the existing \u201cGeneration X\u201d roots (X1 and X2).<\/p>\n<p>This maintains broad trust compatibility. The new intermediates omit the TLS Client Authentication Extended Key Usage (EKU), addressing an upcoming root program mandate. Let\u2019s Encrypt previously detailed plans to end TLS Client Auth support from February 2026.<\/p>\n<p>Profile-specific timelines vary. Users on the default <a href=\"https:\/\/letsencrypt.org\/docs\/profiles\/#classic\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">classic profile<\/a> switch to Generation Y on May 13, 2026. Those needing legacy TLS client auth can stick with the tlsclient profile, which remains on Generation X until May 2026.<\/p>\n<p>Meanwhile,\u00a0TLS server\u00a0and\u00a0short-lived\u00a0profiles shift to Generation Y this week, enabling opt-in short-lived certificates with IP address support. This marks general availability for short-lived certs, aiding automated renewals and reducing exposure windows.<\/p>\n<p>Shortening lifetimes complies with evolving <a href=\"https:\/\/cabforum.org\/working-groups\/server\/baseline-requirements\/requirements\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CA\/Browser Forum<\/a> Baseline Requirements. Next year, early adopters will test 45-day certificates via tlsserver. Defaults drop to 64 days in 2027, then 45 days in 2028, as detailed in Let\u2019s Encrypt\u2019s <a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-45-days-certificate\/\" target=\"_blank\" rel=\"noreferrer noopener\">lifetime reduction post<\/a>.<\/p>\n<p><strong>Timeline Overview<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Change<\/th>\n<th>Profile Affected<\/th>\n<th>Date<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Gen Y rollout (tlsserver\/shortlived)<\/td>\n<td>tlsserver, shortlived<\/td>\n<td>This week<\/td>\n<\/tr>\n<tr>\n<td>TLS Client Auth end<\/td>\n<td>All (tlsclient legacy)<\/td>\n<td>Feb 2026<\/td>\n<\/tr>\n<tr>\n<td>Gen Y default switch<\/td>\n<td>Classic<\/td>\n<td>May 13, 2026<\/td>\n<\/tr>\n<tr>\n<td>45-day opt-in<\/td>\n<td>tlsserver<\/td>\n<td>2026<\/td>\n<\/tr>\n<tr>\n<td>Default 64 days<\/td>\n<td>All<\/td>\n<td>2027<\/td>\n<\/tr>\n<tr>\n<td>Default 45 days<\/td>\n<td>All<\/td>\n<td>2028<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>These updates <a href=\"https:\/\/community.letsencrypt.org\/t\/upcoming-changes-to-let-s-encrypt-certificates\/243873\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">strengthen<\/a> security by minimizing key compromise risks through shorter validity and refined EKUs, without disrupting most workflows. Let\u2019s Encrypt urges reviewing linked posts and community forums for edge cases, like <a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-started-to-issue\/\" target=\"_blank\" rel=\"noreferrer noopener\">IP certificates<\/a> .<\/p>\n<p>As support on Let\u2019s Encrypt grows, securing over 300 million domains, these changes underscore proactive adaptation to industry standards, potentially influencing broader PKI ecosystems.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-unveils-new-generation-y-root\/\">Let\u2019s Encrypt Unveils New \u201cGeneration Y\u201d Root and 45-Day Certificates<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-unveils-new-generation-y-root\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Let\u2019s Encrypt Unveils New \u201cGeneration Y\u201d Root and 45-Day Certificates Let\u2019s Encrypt, the nonprofit certificate authority powering free TLS\/SSL certificates for millions of websites, announced sweeping updates to its issuance policies. The changes introduce a new \u201cGeneration Y\u201d root hierarchy, deprecate TLS client authentication, and progressively shorten certificate lifetimes to align with CA\/Browser Forum requirements. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-9308","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9308"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9308"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9308\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}