Skip to main content
Cloud & AI Hub
Browse
Glossary AI Directory Playgrounds Models Prompts Explainers Strategy Matrix Benchmark Decoder

Let's Encrypt

The free, automated certificate authority that made HTTPS universal — 90-day certificates issued via the ACME protocol, renewed by software instead of humans.

Last reviewed: July 25, 2026

What is Let’s Encrypt?

Let’s Encrypt is a nonprofit certificate authority that issues domain-validated TLS certificates free, via the ACME protocol: your client proves domain control (an HTTP file or DNS record challenge), receives a certificate, and repeats automatically before expiry. Launched in 2015 when certificates cost real money and were installed by hand annually, it now underpins hundreds of millions of sites — the single biggest reason the web’s HTTPS share went from ~40% to ~95%+.

The 90-day design argument

Short lifetimes look inconvenient and are the point: they bound the damage window of a compromised key, and they force automation — nobody renews manually every 90 days, so the ecosystem built tooling (Certbot, Caddy’s built-in ACME, cert-manager for Kubernetes, load balancers with ACME integrations) that made expiry a solved problem for those who adopted it. The industry agreed with the logic: maximum certificate lifetimes have been ratcheting down ever since, making ACME-style automation mandatory everywhere, paid CAs included.

Choosing challenge types

HTTP-01 is simplest but requires port-80 reachability per host. DNS-01 proves control via DNS record — the only route to wildcard certificates and the right choice for internal hosts that aren’t internet-reachable, at the cost of granting your ACME client DNS-write credentials (scope them narrowly; that credential is now security-critical).

What people get wrong

  • Automating issuance but not alerting — renewal silently breaking (moved DNS, changed firewall) surfaces as an outage 60 days later; monitor expiry independently.
  • Hitting rate limits during incidents: per-domain issuance limits punish tight retry loops; use the staging environment for testing.
  • Treating DV as identity assurance — Let’s Encrypt proves domain control, nothing about the organization behind it; phishing sites have padlocks too.

Primary source: Let’s Encrypt — How It Works

Why Let’s Encrypt Changed TLS Adoption

Before Let’s Encrypt launched in 2016, obtaining a TLS certificate typically required paying a commercial certificate authority and often navigating a manual validation process, which was enough friction that a meaningful portion of the web ran unencrypted over plain HTTP. Let’s Encrypt’s free, fully automated certificate issuance — using the ACME protocol to programmatically verify domain ownership and issue a certificate in seconds — removed both the cost and manual-process barriers, and is widely credited as a major driver of the web’s shift toward HTTPS becoming the near-universal default rather than a paid, optional upgrade. Certificates from Let’s Encrypt are valid for 90 days rather than the year or more common with commercial certificate authorities, a deliberate design choice that encourages automated renewal (via tools like Certbot) as standard practice, reducing the risk of expired-certificate outages that longer validity periods can make easier to overlook.

Advertisement (In-Content)

Historical figures and technical concepts for informational purposes only. Not technical, professional, legal, or financial advice. Sources: Official Documentation.