{"id":9964,"date":"2026-01-18T10:03:43","date_gmt":"2026-01-18T10:03:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/18\/lets-encrypt-has-made-6-day-ip-based-tls-certificates-generally-available\/"},"modified":"2026-01-18T10:03:43","modified_gmt":"2026-01-18T10:03:43","slug":"lets-encrypt-has-made-6-day-ip-based-tls-certificates-generally-available","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/18\/lets-encrypt-has-made-6-day-ip-based-tls-certificates-generally-available\/","title":{"rendered":"Let\u2019s Encrypt has made 6-day IP-based TLS certificates Generally Available"},"content":{"rendered":"<p>    Let\u2019s Encrypt has made 6-day IP-based TLS certificates Generally Available<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Let\u2019s Encrypt, a key provider of free TLS certificates, has rolled out short-lived and IP address-based certificates for general use. These new options became available starting in early 2026, addressing long-standing issues in certificate security.<\/p>\n<p>Short-lived certificates last just 160 hours, about six and a half days, while IP-based ones tie directly to IP addresses instead of domain names. Users activate them by choosing the \u201cshort-lived\u201d profile in their ACME client.<\/p>\n<p>This move comes as organizations push for stronger TLS protections amid rising key compromises and <a href=\"https:\/\/cybersecuritynews.com\/supply-chain-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">supply chain attacks<\/a>. Let\u2019s Encrypt announced the general availability in a blog post, building on beta tests from late 2025.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Short-Lived Certificates Boost Security<\/strong><\/h2>\n<p>Traditional TLS certificates last up to 90 days, creating wide windows for damage if private keys leak. Attackers can exploit stolen keys until revocation kicks in or the certificate expires.<\/p>\n<p>But revocation systems, like <a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-ocsp-end-support\/\" target=\"_blank\" rel=\"noreferrer noopener\">CRLs and OCSP<\/a>, often fail many clients ignore them due to latency or misconfiguration. Short-lived certificates cut this risk sharply.<\/p>\n<p>By forcing renewal every six days, they demand fresh validation against the certificate authority (CA). This reduces reliance on flaky revocation. If a key compromises, the certificate dies fast, limiting exposure to hours, not weeks.<\/p>\n<p>Let\u2019s Encrypt emphasizes that this is an opt-in feature only. Automated setups renew effortlessly via ACME, but manual users may prefer to keep longer lifetimes for now.<\/p>\n<p>The team plans to halve default lifetimes to 45 days over the next few years, as outlined in their <a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-ip-certificates\/\" target=\"_blank\" rel=\"noreferrer noopener\">December 2025 update<\/a>. This gradual shift encourages automation without disruption. Early adopters report smooth operations, proving short-lived certs scale for production.<\/p>\n<h2 class=\"wp-block-heading\"><strong>IP Address Certificates Fill a Key Gap<\/strong><\/h2>\n<p>IP-based certificates let servers authenticate TLS over raw IP addresses, supporting both IPv4 and IPv6. Unlike domain certs, which use DNS validation, these bind to specific IPs via IP address validation methods. Let\u2019s Encrypt <a href=\"https:\/\/letsencrypt.org\/2026\/01\/15\/6day-and-ip-general-availability\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">mandates<\/a> they be short-lived, recognizing IPs change often think dynamic cloud instances or mobile networks.<\/p>\n<p>Use cases include legacy systems without domains, containerized apps on private nets, and quick TLS for test environments. Validation happens via ACME challenges proving control of the IP, often through direct connection. Let\u2019s Encrypt issued its first IP cert in July 2025, validating the approach.<\/p>\n<p>Security experts praise this for closing gaps in hybrid networks. Firewalls and load balancers can now secure IP-only traffic without workarounds like self-signed certs.<\/p>\n<p>For threat hunters and SecOps, these certs mean tighter key rotation and less revocation chasing. Integrate them into <a href=\"https:\/\/cybersecuritynews.com\/secure-your-ci-cd-pipeline\/\" target=\"_blank\" rel=\"noreferrer noopener\">CI\/CD pipelines <\/a>for zero-trust setups. Monitor via tools like Certificate Transparency logs to spot anomalies early.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-6-day-tls-certificates\/\">Let\u2019s Encrypt has made 6-day IP-based TLS certificates Generally Available<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-6-day-tls-certificates\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Let\u2019s Encrypt has made 6-day IP-based TLS certificates Generally Available Let\u2019s Encrypt, a key provider of free TLS certificates, has rolled out short-lived and IP address-based certificates for general use. These new options became available starting in early 2026, addressing long-standing issues in certificate security. Short-lived certificates last just 160 hours, about six and a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-9964","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9964"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9964"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9964\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}