# Upcoming Changes to Let’s Encrypt Certificates

**URL:** <https://community.letsencrypt.org/t/upcoming-changes-to-let-s-encrypt-certificates/243873>\
**Category:** API Announcements\
**Created:** [December 15, 2025, 7:16pm UTC](https://community.letsencrypt.org/t/upcoming-changes-to-let-s-encrypt-certificates/243873 "2025-12-15T19:16:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mcpherrinm](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mcpherrinm/32/59604_2.png) [@mcpherrinm](https://community.letsencrypt.org/u/mcpherrinm)\
**Post date:** [December 15, 2025, 7:16pm UTC](https://community.letsencrypt.org/t/upcoming-changes-to-let-s-encrypt-certificates/243873/1 "2025-12-15T19:16:59Z")

</div>

Let’s Encrypt is introducing several updates to the certificates we issue, including new root certificates, the deprecation of TLS client authentication, and shortening certificate lifetimes. To help roll out changes gradually, we’re making use of [ACME profiles](https://letsencrypt.org/2025/01/09/acme-profiles) to allow users to have control over when some of these changes take place. For most users, no action is required.

Let’s Encrypt has generated two new Root Certification Authorities (CAs) and six new Intermediate CAs, which we’re collectively calling the “Generation Y” hierarchy. These are cross-signed from our existing “Generation X” roots, X1 and X2, so will continue to work anywhere our current roots are trusted.

Most users get certificates from our default [classic](https://letsencrypt.org/docs/profiles/#classic) profile, unless they’ve opted into another profile. This profile will switch to the new Generation Y hierarchy on May 13 2026. These new intermediates do not contain the “TLS Client Authentication” Extended Key Usage due to an upcoming root program requirement. We have previously announced our plans to [end TLS Client Authentication](https://letsencrypt.org/2025/05/14/ending-tls-client-authentication) starting in February 2026, which will coincide with the switch to the Generation Y hierarchy. Users who encounter issues or need an extended period to switch can use our [tlsclient](https://letsencrypt.org/docs/profiles/#tlsclient) profile until May 2026, which will also remain on our existing Generation X roots.

If you’re requesting certificates from our [tlsserver](https://letsencrypt.org/docs/profiles/#tlsserver) or [shortlived](https://letsencrypt.org/docs/profiles/#shortlived) profiles, you’ll begin to see certificates which come from the Generation Y hierarchy this week. This switch will also mark the opt-in general availability of short-lived certificates from Let’s Encrypt, including support for IP Addresses on certificates.

We also announced our timeline to comply with upcoming changes to the [CA/Browser Forum Baseline Requirements](https://cabforum.org/working-groups/server/baseline-requirements/requirements/), which will require us to shorten the length of time our certificates are valid for. Next year, you’ll be able to opt-in to 45 day certificates for early adopters and testing via the tlsserver profile. In 2027, we’ll lower the default certificate lifetime to 64 days, and then to 45 in 2028. For the full timeline and details, please see our post on [decreasing certificate lifetimes to 45 days](https://letsencrypt.org/2025/12/02/from-90-to-45).

For most users, no action is required, but we recommend reviewing the linked blog posts announcing each of these changes for more details. If you have any questions, please do not hesitate to ask here, on this forum.

---

<div class="post-metadata">

**Author:** ![mcpherrinm](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mcpherrinm/32/59604_2.png) [@mcpherrinm](https://community.letsencrypt.org/u/mcpherrinm)\
**Post date:** [December 19, 2025, 8:38pm UTC](https://community.letsencrypt.org/t/upcoming-changes-to-let-s-encrypt-certificates/243873/2 "2025-12-19T20:38:15Z")

</div>

The previously announced Generation Y switch for the tlsserver and shortlived profiles has been delayed to January 7, 2026. We require additional internal changes to complete this transition, which need to happen after our end-of-year deployment freeze.

---

<div class="post-metadata">

**Author:** ![Phil](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/phil/32/76801_2.png) [@Phil](https://community.letsencrypt.org/u/Phil)\
**Post date:** [January 7, 2026, 5:55pm UTC](https://community.letsencrypt.org/t/upcoming-changes-to-let-s-encrypt-certificates/243873/3 "2026-01-07T17:55:43Z")

</div>

The [Generation Y hierarchy](https://letsencrypt.org/certificates/) is now generally available for the [tlsserver](https://letsencrypt.org/docs/profiles/#tlsserver) and [shortlived](https://letsencrypt.org/docs/profiles/#shortlived) profiles. Happy issuance! :letsencrypt:🎉🎊
