Profiles and Lifetimes

Profiles, Shrinking Lifetimes and IP Address Certificates

A profile is a named certificate recipe in the CA's ACME directory, requested with --preferred-profile or --required-profile (which fails rather than fall back), Certbot 4.0 1,690 onward.

Let's Encrypt 1,144 profiles on 23 September 2026 (tlsclient was withdrawn on 8 July 2026)
Profile Lifetime Names IP addresses Authorization reuse
classic (default) 90 days Up to 100 No 30 days
tlsserver 45 days Up to 25 No 7 hours
shortlived 160 hours (about 6 days) Up to 25 Yes 7 hours

classic drops to 64 days on 10 February 2027 and 45 days on 16 February 2028; the Baseline Requirements cap public CAs at 100 days from 15 March 2027 and 47 from 15 March 2029. IP address certificates (generally available since 15 January 2026) need shortlived and Certbot 5.4's webroot, standalone or manual plugin. Pebble 789 issued one (test options as in Certbot):

A six-day certificate for an IP addressShell
sudo certbot certonly --preferred-profile shortlived --webroot -w /var/www/example \
  --ip-address 127.0.0.1 --cert-name ip-test
Output
Requesting a certificate for 127.0.0.1
...
This certificate expires on 2026-09-29.

Let's Encrypt ended OCSP on 6 August 2025 (revocation is CRL-only, so leave SSLUseStapling off) and its expiry e-mails in June 2025. Rate limits: 50 new certificates per registered domain and 5 per identical name set every 7 days, 300 new orders per account every 3 hours, 5 failed validations per name per hour. Renewals skip the domain and order limits, ARI renewals skip all, and staging (--test-cert) allows far more.