100-day TLS certificates

The public maximum is already 200 days. 100 days is next. 47 days follows.

The CA/B Forum caps

Publicly trusted TLS certificates are capped by CA/B Forum ballot, not by your ACME client. The dates that matter:

Let’s Encrypt and other public CAs will not issue longer than the cap in force on the issue date. Private PKI is a different world and is not covered here.

Renewals per year

A rough integer is enough for capacity planning: ceil(365 / max lifetime that year).

That is why a monitor that only emails once, a week out, gets worse every time the cap drops. There are more chances to miss a reload, and less calendar to recover.

What to do

Automate issuance (Certbot, lego, Caddy, or your CA’s ACME). Then monitor the live handshake, because automation fails in ways logs do not surface. Use the lifetime calculator if you want the 2026 / 2027 / 2029 numbers for a given issue date, and check a host if you want days remaining on the wire.

SSLert does not issue certificates. It tells you when the one you are actually serving will die.

Check a certificate