Home
Web Hosting
Domains FAQ
Resources
About Contact Client Portal
Guides ยท ยท 10 min read

Let's Encrypt Free SSL in 2026: Setup, Renewal and Shorter Certificates

ยท 10 min read

A Let's Encrypt free SSL certificate gives your site the same browser-trusted HTTPS protection as a paid domain-validated certificate, at no cost. Let's Encrypt is run by the nonprofit Internet Security Research Group and issues certificates automatically to anyone who can prove they control a domain. The catch is that its certificates are short-lived, and in 2026 they are getting shorter, so the real skill is not getting a certificate but making sure it renews itself.

This guide covers what a Let's Encrypt free SSL certificate does and does not give you, the lifetime changes coming between now and 2029, how to set one up on shared hosting or a VPS, wildcard certificates, the mistakes that break renewals, what it means for privacy, and when paying for SSL still makes sense.

The short version

On shared hosting, turn on the free certificate in your control panel. On a VPS, use Caddy, which handles certificates on its own, or Certbot with Nginx or Apache. If you use the standard HTTP-01 validation, keep port 80 reachable. Check that renewal works with certbot renew --dry-run, and set up your own expiry monitoring, because Let's Encrypt stopped sending expiry emails in June 2025. Never plan on renewing by hand: certificates drop to 45 days by 2028.

What a Let's Encrypt free SSL certificate gives you

What you get

  • The same browser-trusted HTTPS protection as a paid domain-validated certificate
  • Trust in every major browser and operating system
  • Certificates for single names, several names, or a whole subdomain level with a wildcard
  • Issuance and renewal with no sign-up, no payment and no human in the loop

What you do not get

  • Organisation validation (OV) or extended validation (EV): Let's Encrypt only proves control of the domain, not who owns the business
  • A warranty or a support line; help comes from the community forum
  • Long lifetimes: certificates last 90 days today, and less from 2027

Certificate lifetimes are getting shorter

In April 2025 the CA/Browser Forum, which sets the rules every public certificate authority follows, approved a schedule that cuts the maximum lifetime of all public TLS certificates, paid ones included. Let's Encrypt announced its own steps in December 2025.

Date What changes
15 March 2026 Industry maximum drops to 200 days, so even a paid "one-year" certificate must now be reissued during the year
13 May 2026 Let's Encrypt offers 45-day certificates through its opt-in tlsserver profile
10 February 2027 Let's Encrypt's default certificates drop from 90 to 64 days
15 March 2027 Industry maximum drops to 100 days
16 February 2028 Let's Encrypt's default certificates drop to 45 days
15 March 2029 Industry maximum drops to 47 days

Let's Encrypt says most automated setups need no changes, but it recommends checking that your renewal process copes with shorter lifetimes, using a client that supports ACME Renewal Information (ARI) so the CA can tell it when to renew, and renewing at about two thirds of a certificate's life rather than on a fixed 60-day schedule. Anyone still installing certificates by hand would have to do it at least eight times a year by 2028.

Three ways to get a Let's Encrypt free SSL certificate

EasiestShared or WordPress hosting

Most hosting control panels issue and renew a free certificate for you. You switch it on once per domain, and the panel handles the rest.

No setupCaddy on a VPS

Caddy serves every site over HTTPS by default and obtains and renews certificates itself, as long as your DNS points to the server and ports 80 and 443 are reachable. Our Docker hosting guide shows a working Caddy setup.

Most commonCertbot with Nginx or Apache

Certbot is the Electronic Frontier Foundation's client for Let's Encrypt. It requests the certificate, edits your web server configuration to use it, and installs a timer that renews it automatically. The steps follow below.

Setting up Certbot on a VPS, step by step

These commands put a Let's Encrypt free SSL certificate on a Debian or Ubuntu server running Nginx. For Apache, install python3-certbot-apache instead and use --apache.

1Point the domain at your server

Create an A record for your domain, and an AAAA record only if your server answers correctly on that IPv6 address. Let's Encrypt tries IPv6 first when an AAAA record exists. It falls back to IPv4 only if the IPv6 connection times out, so an IPv6 address that answers with the wrong server makes validation fail.

2Open ports 80 and 443

The standard HTTP-01 check only works on port 80, so leave it open even if your site redirects everything to HTTPS. With UFW:

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

3Install Certbot

sudo apt update
sudo apt install certbot python3-certbot-nginx

Your distribution's package works and renews automatically. Certbot's own documentation recommends its snap package instead, because distribution packages fall behind: Debian 13 ships Certbot 4.0, while 4.1, released in June 2025, added support for ARI.

4Get the certificate

sudo certbot --nginx -d example.com -d www.example.com

Certbot proves you control the domain, fetches the certificate and updates your Nginx configuration to use it. It asks for an email address. Since Let's Encrypt no longer sends expiry emails, you can skip it by adding --register-unsafely-without-email.

5Prove that renewal works

sudo certbot renew --dry-run
systemctl status certbot.timer

The dry run tests the whole renewal against Let's Encrypt's staging system without issuing a real certificate, and the timer is what runs the real renewals. If both look fine, you are done.

6Watch the expiry date yourself

Let's Encrypt ended its expiry reminder emails on 4 June 2025 and recommends a monitoring service instead. Any uptime monitor that checks certificate expiry will do, including a self-hosted one such as Uptime Kuma.

Wildcard certificates need a DNS challenge

A wildcard certificate such as *.example.com covers every subdomain at that level. Let's Encrypt only issues wildcards through the DNS-01 challenge, where your ACME client publishes a TXT record at _acme-challenge.example.com to prove control. To renew automatically, the client needs API access to your DNS provider, usually through a Certbot DNS plugin. A wildcard you validate by adding the TXT record by hand cannot renew on its own, which will not survive the move to 45-day certificates.

Mistakes that break Let's Encrypt renewals

Getting a Let's Encrypt free SSL certificate the first time is easy. These are the usual reasons the renewal fails weeks later.

1. Closing port 80 when you use HTTP-01

HTTP-01, the method in the Certbot example above, only works on port 80. Close it in a firewall clean-up and the next renewal fails. DNS-01 validates through a DNS record and TLS-ALPN-01 over port 443, so neither needs port 80.

2. A stale AAAA record

Let's Encrypt prefers IPv6 and only falls back to IPv4 on a timeout. An AAAA record pointing at an old server that still answers makes validation fail, and there is no setting to make it prefer IPv4. Fix or remove the record.

3. Hitting rate limits while testing

Let's Encrypt allows 50 certificates per registered domain and 5 for the same exact set of names every 7 days. Repeating real requests while you debug uses them up. Test with --dry-run, which uses the staging system.

4. Relying on a renewal you never tested

A renewal that worked once can break after a configuration change. Re-run the dry run after any change to your web server, firewall or DNS, and keep your expiry monitor running.

Let's Encrypt free SSL and your privacy

Let's Encrypt submits every certificate it issues to public Certificate Transparency logs, as all public certificate authorities do. Anyone can search those logs, with tools such as crt.sh, and see every hostname you have ever had a certificate for. If a subdomain's name gives away something you would rather keep quiet, such as an internal tool or a client's name, use a wildcard certificate, which publishes only *.example.com, or do not put it on a public certificate at all.

On the other side, Let's Encrypt asks for very little. There is no sign-up form, no payment and no proof of identity, and since it ended expiry emails partly so it would no longer have to keep millions of email addresses tied to issuance records, you can register without one.

Free SSL or paid SSL?

For most sites a Let's Encrypt free SSL certificate is the right choice. A paid domain-validated certificate provides the same browser-trusted HTTPS protection, and paying does not make the encrypted connection any stronger. Since March 2026 it also has to be reissued at least every 200 days. Paying makes sense when you need what a free certificate cannot show:

  • Organisation or extended validation, when a contract, regulator or procurement process requires your company's verified name inside the certificate. Visitors will rarely see it: Chrome moved the EV indicator out of the address bar in 2019.
  • Vendor support, if you want someone to call when something goes wrong.
  • A different CA, if you want a backup issuer for critical services in case one CA has an outage.

SSL on Packetra hosting

Every shared hosting and WordPress hosting plan includes a free SSL certificate, which you switch on from the control panel. On a Cloud VPS you have full root access, so Certbot or Caddy work exactly as described above, in Finland or Switzerland. If you are moving an existing site, our guide to migrating without downtime covers getting the certificate in place before you switch DNS.

FAQ

Is Let's Encrypt really free?

Yes. Let's Encrypt is run by the nonprofit Internet Security Research Group, funded by sponsors and donations, and charges nothing for certificates or renewals.

Is a Let's Encrypt free SSL certificate as secure as a paid one?

The encryption is the same. Paid certificates can add verified company details (OV or EV), a warranty and support, but they do not encrypt traffic any better.

How long does a Let's Encrypt certificate last?

90 days by default today. The default drops to 64 days on 10 February 2027 and to 45 days on 16 February 2028, and a 45-day option has been available since May 2026. Automatic renewal makes the length irrelevant in practice.

Can I get a wildcard certificate from Let's Encrypt?

Yes, through the DNS-01 challenge. For automatic renewal your ACME client needs API access to your DNS provider.

Why did my Let's Encrypt renewal fail?

Usually port 80 is closed on a setup that uses HTTP-01, the domain's A or AAAA record points somewhere else, or the web server configuration changed. Run sudo certbot renew --dry-run to see the exact error.

Is a Let's Encrypt free SSL certificate enough for an online shop?

For encryption, yes: browsers treat it exactly like a paid domain-validated certificate. If a payment provider, bank or customer contract asks for an organisation-validated certificate, that requirement decides it, not the encryption.

Can Let's Encrypt issue a certificate for an IP address?

Yes, since January 2026, but only as a short-lived certificate valid for about six days, so it only suits fully automated setups.

Sources

Last reviewed: 9 October 2026

Research note: Lifetime dates come from Let's Encrypt's announcement and the CA/Browser Forum schedule as reported at the time of review. Let's Encrypt applies changes at your next renewal after each date, and dates can move, so check the linked pages before relying on them.

Need Reliable Hosting?

Privacy-focused, anonymous, and built for people who value their data.