SSL Certificates are getting shorter, and that’s a good thing.

SSL certificates are one of those things we barely notice until they expire. Now their lifetime is getting much shorter. It sounds inconvenient, but I think it says something useful about where infrastructure is going: automate it or eventually regret it.

SSL certificates are probably one of the least exciting parts of running anything on the web. When everything works, nobody thinks about them. You type a URL, see HTTPS and move on. When a certificate expires, though, suddenly everyone cares. Browsers complain, users think the site has been hacked and somebody has to figure out why the renewal didn’t happen.

This is becoming more interesting because certificate lifetimes are getting shorter. Let’s Encrypt still issues 90-day certificates by default today, but it plans to move to 64 days in February 2027 and 45 days in February 2028. The wider industry is moving in the same direction, with publicly trusted certificates limited to a maximum of 47 days from March 2029.

At first that sounds annoying. More renewals, more opportunities for something to fail. But that’s really the wrong way to look at it. Shorter certificates reduce how long a compromised or incorrectly issued certificate can remain useful, which is one of the reasons the industry has been reducing certificate lifetimes for years.

The more interesting part for me is what this forces us to do operationally. If you’re still manually renewing certificates, a 45-day lifetime is going to become painful very quickly. And that’s probably a good thing. Certificate renewal should be boring automation. Let’s Encrypt itself recommends automated renewal and says most users with properly automated issuance shouldn’t need to change much.

It’s a small example of something I see everywhere in IT. We often keep manual processes simply because they work and nobody has had a reason to fix them. Then the environment changes and suddenly that little manual job becomes a liability. Certificates are doing exactly that. The technology isn’t becoming harder. It’s pushing us towards better habits.

I actually like changes like this. Not because I particularly enjoy thinking about certificates, I really don’t, but because good infrastructure should quietly maintain itself. The less often a human needs to remember that something expires on a Tuesday afternoon, the better the system probably is.

I certificati SSL sono una di quelle parti dell’infrastruttura che preferisco dimenticare. Se funzionano, bene. Non c’è molto altro da dire. Poi un giorno qualcosa non si rinnova, il browser comincia a mostrare avvisi inquietanti e improvvisamente il certificato che nessuno considerava diventa il problema più importante della giornata.

La cosa interessante è che nei prossimi anni dovremo rinnovarli molto più spesso. Let’s Encrypt oggi utilizza ancora 90 giorni come durata standard, ma passerà a 64 giorni nel febbraio 2027 e poi a 45 giorni nel febbraio 2028. Dal marzo 2029 le regole del settore limiteranno i certificati pubblicamente attendibili a un massimo di 47 giorni.

La prima reazione potrebbe essere: fantastico, un’altra cosa che può rompersi più spesso. In realtà il motivo ha senso. Se una chiave viene compromessa o un certificato viene emesso erroneamente, una durata più breve riduce il tempo durante il quale quel certificato può continuare ad essere utilizzato.

Però la parte che trovo più interessante non è nemmeno quella. È il fatto che una durata di 45 giorni rende abbastanza assurdo continuare a gestire i rinnovi manualmente. Se ogni mese devi ricordarti di entrare da qualche parte, generare qualcosa e installarlo su un server, prima o poi te lo dimentichi. Let’s Encrypt stessa spinge da tempo verso rinnovi automatici e, per chi ha già un sistema automatizzato correttamente, il cambiamento dovrebbe essere quasi invisibile.

È una dinamica che vedo spesso nell’IT. Abbiamo procedure manuali che continuiamo ad utilizzare semplicemente perché hanno sempre funzionato. Magari richiedono cinque minuti ogni tre mesi, quindi nessuno perde tempo ad automatizzarle. Poi cambia qualcosa e quei cinque minuti diventano improvvisamente un problema operativo.

Alessio

Technology consultant, software builder and problem solver, sharing practical thoughts on tech, operations and digital products.