# Supporting validity periods shorter than 90d (e.g. 30 days)

**URL:** <https://community.letsencrypt.org/t/supporting-validity-periods-shorter-than-90d-e-g-30-days/186640>\
**Category:** Issuance Policy\
**Created:** [October 24, 2022, 11:13am UTC](https://community.letsencrypt.org/t/supporting-validity-periods-shorter-than-90d-e-g-30-days/186640 "2022-10-24T11:13:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stanwise](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stanwise/32/15929_2.png) [@stanwise](https://community.letsencrypt.org/u/stanwise)\
**Post date:** [October 24, 2022, 11:13am UTC](https://community.letsencrypt.org/t/supporting-validity-periods-shorter-than-90d-e-g-30-days/186640/1 "2022-10-24T11:13:05Z")

</div>

There are sometimes legitimate use-cases for requesting certificates valid for less than 90d. Also in previous communications, you've mentioned you're looking into shortening validity periods in the future. Do you have any update on the plans? Would you be open to supporting it?

The most related post I found is from 2017, but the realities were different then (e.g. LE was sill using the draft ACME version): [Shorter validity period for certificates - #6 by josh](https://community.letsencrypt.org/t/shorter-validity-period-for-certificates/25709/6)

---

<div class="post-metadata">

**Author:** ![jvanasco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jvanasco/32/55900_2.png) [@jvanasco](https://community.letsencrypt.org/u/jvanasco)\
**Post date:** [October 24, 2022, 2:37pm UTC](https://community.letsencrypt.org/t/supporting-validity-periods-shorter-than-90d-e-g-30-days/186640/2 "2022-10-24T14:37:06Z")

</div>

The LetsEncrypt staff shared some insight into this with the Community Moderators earlier this year. It is still on their radar and something they want to offer, but it is not likely to happen in the near future. They have a backlog of higher priority items to get through, and will then have to address some staffing implications before offering this.

It seems that ISRG is basically at an operational sweet spot of 90 day lifetimes right now. As shorter lifetimes will mean more certificates, higher server load, and would make any outage even more critical, they would need to staff up engineering resources to handle everything with the same level of attention and reliability. They don't want to overextend their personnel.

---

<div class="post-metadata">

**Author:** ![rmbolger](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rmbolger/32/27474_2.png) [@rmbolger](https://community.letsencrypt.org/u/rmbolger)\
**Post date:** [October 24, 2022, 2:43pm UTC](https://community.letsencrypt.org/t/supporting-validity-periods-shorter-than-90d-e-g-30-days/186640/3 "2022-10-24T14:43:18Z")

</div>

If you're just looking for any free ACME CA that supports shorter lifetimes, [Google Trust Services](https://pki.goog) already does via the [Certificate Manager Public CA](https://cloud.google.com/certificate-manager/docs/public-ca) feature in Google Cloud. However, your ACME client needs to be able to support sending the necessary `notBefore` and `notAfter` fields in some form or another which not all currently do.

You can go as low as 1 day lifetime with Google, but they recommend no shorter than 3 days.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [November 23, 2022, 2:44pm UTC](https://community.letsencrypt.org/t/supporting-validity-periods-shorter-than-90d-e-g-30-days/186640/4 "2022-11-23T14:44:17Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
