A profile is a named certificate recipe in the CA's ACME directory, requested with --preferred-profile or --required-profile (which fails rather than fall back), Certbot 4.0 1,690 onward.
| Profile | Lifetime | Names | IP addresses | Authorization reuse |
|---|---|---|---|---|
| classic (default) | 90 days | Up to 100 | No | 30 days |
| tlsserver | 45 days | Up to 25 | No | 7 hours |
| shortlived | 160 hours (about 6 days) | Up to 25 | Yes | 7 hours |
classic drops to 64 days on 10 February 2027 and 45 days on 16 February 2028; the Baseline Requirements cap public CAs at 100 days from 15 March 2027 and 47 from 15 March 2029. IP address certificates (generally available since 15 January 2026) need shortlived and Certbot 5.4's webroot, standalone or manual plugin. Pebble 789 issued one (test options as in Certbot):
sudo certbot certonly --preferred-profile shortlived --webroot -w /var/www/example \
--ip-address 127.0.0.1 --cert-name ip-testRequesting a certificate for 127.0.0.1 ... This certificate expires on 2026-09-29.
Let's Encrypt ended OCSP on 6 August 2025 (revocation is CRL-only, so leave SSLUseStapling off) and its expiry e-mails in June 2025. Rate limits: 50 new certificates per registered domain and 5 per identical name set every 7 days, 300 new orders per account every 3 hours, 5 failed validations per name per hour. Renewals skip the domain and order limits, ARI renewals skip all, and staging (--test-cert) allows far more.