Let's Encrypt will transition to 64-day certificate lifetimes by default on February 10, 2027, with staging environment testing beginning October 14, 2026. Organizations should update renewal processes to trigger at approximately two-thirds of certificate lifetime and prepare for further reductions to 45 days in 2028, while authorization reuse periods will decrease from 30 days to 10 days.
Attackers compromised three country-code top-level domains (.gh, .sl, .as) and obtained unauthorized HTTPS certificates for Google and YouTube domains in late September. Google blocked the certificates through Chrome's CRLSets and worked with certificate authorities to revoke them, though the attack also affected other organizations and the longest gap between certificate issuance and revocation was nearly a week.
A developer uses Dokku with a wildcard DNS record to quickly deploy temporary applications without the overhead of setting up new domains and certificates. By pointing *.apps.foo.tools to the Dokku server, they can spin up and destroy minimal apps in seconds, with examples showing a Node.js hello world and a Bun-based SQLite hit counter that persists data via mounted storage.