[{"data":1,"prerenderedAt":110},["ShallowReactive",2],{"seo-verification":3,"blog-certificats-tls-courts-automatiser-acme-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"id":7,"slug":8,"title":9,"excerpt":10,"readTime":11,"views":12,"isPinned":13,"publishedAt":14,"category":15,"categories":21,"featuredImage":23,"bgImage":24,"posterImage":25,"relatedSolution":23,"intro":26,"sections":27,"ctaTitle":69,"ctaBody":70,"ctaButton":71,"ctaUrl":72,"relatedPosts":73},204,"certificats-tls-courts-automatiser-acme","Short TLS certificates: automate with ACME","TLS certificates will shrink to 47 days by 2029. Here is how to automate renewal with ACME to prevent any service interruption.",7,0,false,"2026-08-01T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":20},8,"Security & Monitoring","securite-monitoring","bg-rose-500\u002F10 text-rose-400","security",[22],{"id":16,"name":17,"slug":18,"color":19,"icon":20},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fcertificats-tls-courts-automatiser-acme-poster.svg","The CA\u002FB Forum has made its decision: TLS certificate validity periods will shorten progressively. Currently capped at 398 days, they will be limited to 100 days from March 2027, then to 47 days by 2029. This timeline forces teams managing certificates manually to rethink their processes. Automating renewal via the ACME protocol is no longer a comfortable option — it is an operational necessity.",[28,32,41,44,63,66],{"type":29,"title":30,"body":31},"h2","Why certificates are getting shorter","In July 2026, AWS announced native ACME protocol support in its certificate management services, a strong signal that the industry is converging on mandatory automation. The CA\u002FB Forum voted on a progressive validity reduction schedule with a dual goal: limit exposure to compromised keys and force regular renewal of cryptographic parameters. An expired certificate or one relying on an old key represents a measurable attack surface. Shortening the validity period mechanically reduces this window, provided renewal is reliable and automatic.",{"type":33,"title":34,"items":35},"ul","The concrete risks of manual renewal",[36,37,38,39,40],"**Silent expiration** — a manually renewed certificate depends on a calendar alert or a human reminder, two mechanisms that regularly fail during busy periods or team changes.","**Late alerts** — standard monitoring tools warn about expiration at 30 days, a margin designed for annual certificates; with 47-day certificates, this window no longer provides enough time to act calmly.","**Frozen cryptographic parameters** — manual renewal encourages reusing the same configuration; automation instead enforces a key and hash policy applied consistently.","**SLA impact** — a service interruption caused by an expired certificate creates contractual liability and damages the platform's reputation.","**Growing operational burden** — moving from one renewal per year to eight renewals per year per domain multiplies manual workload without added value for technical teams.",{"type":29,"title":42,"body":43},"The timeline: what changes and when","The current maximum validity period is 398 days, a cap set after browsers stopped trusting certificates exceeding that limit. The CA\u002FB Forum voted in 2024 on a progressive schedule: from March 2027, the maximum duration will be reduced to 100 days. A second step, planned for 2029, will lower this cap to 47 days. Let's Encrypt is already anticipating this trajectory by issuing 90-day certificates. By 2029, manually managing even a dozen domains will be structurally impossible without automated tooling.",{"type":45,"title":46,"steps":47},"steps","Automating ACME renewal",[48,51,54,57,60],{"title":49,"body":50},"Inventory existing certificates","Before automating, take stock of all active certificates: domains covered, issuing authorities, expiration dates, validation method (HTTP-01, DNS-01, TLS-ALPN-01). On Linux, `certbot certificates` lists managed certificates. For others, `openssl s_client -connect your-domain.com:443` shows the issuer and expiration date.",{"title":52,"body":53},"Choose a suitable ACME client","`certbot` is the EFF's reference client, available in the repositories of all major Linux distributions. `acme.sh` is a shell script with no external dependencies, particularly suited to DNS-01 validation scenarios. If your web server is Caddy, no third-party client is needed: Caddy manages the ACME protocol natively.",{"title":55,"body":56},"Configure automatic renewal","With `certbot`, the package automatically installs a systemd timer that attempts renewal twice a day. Check it is active: `systemctl status certbot.timer`. With `acme.sh`, the command `acme.sh --install-cronjob` adds the necessary cron entry. With 47-day certificates, adjust the renewal threshold to 15 days.",{"title":58,"body":59},"Test renewal before the deadline","Never assume the configuration is correct without verifying it. Run `certbot renew --dry-run` to validate the chain without issuing a real certificate. If the test passes, follow up with `certbot renew --force-renewal` on a non-critical domain to confirm the web server reloads without service interruption.",{"title":61,"body":62},"Monitor with a post-renewal webhook","Configure a post-renewal hook in `certbot` via the `--post-hook` option or in the `\u002Fetc\u002Fletsencrypt\u002Frenewal-hooks\u002Fpost\u002F` directory. This hook can send a notification to an alert channel to confirm renewal completed successfully. A prolonged silence on this channel itself becomes an alert.",{"type":64,"body":65},"tip","Run `certbot renew --force-renewal` on a staging environment several weeks before your first certificates expire. With 47-day validity periods, the window between the first alert and actual expiration will be narrow. A forced test in advance takes a few minutes and eliminates this category of risk.",{"type":29,"title":67,"body":68},"Going further","If you are starting with Let's Encrypt on a VPS, our article on SSL certificates with Let's Encrypt covers the initial setup and edge cases related to wildcards. For new infrastructure, Caddy deserves close attention: its native ACME protocol support completely removes the certificate management layer, with the web server handling it transparently.","Secure infrastructure, without manual TLS configuration","On ServOrbit VPS, certificate management can be integrated from provisioning. Explore our plans designed for teams who want solid security without unnecessary operational overhead.","See our secure plans","\u002Fpourquoi\u002Fsecurite",[74,88,97],{"id":75,"slug":76,"title":77,"excerpt":78,"readTime":16,"views":79,"isPinned":13,"publishedAt":80,"category":81,"categories":82,"featuredImage":23,"bgImage":24,"posterImage":84,"relatedSolution":85},116,"certificats-ssl-lets-encrypt-vps","Free SSL Certificates with Let's Encrypt on a VPS","Deploy Let's Encrypt on your VPS: free HTTPS, automatic renewal, an A+ on SSL Labs with Nginx, Caddy or Traefik in Docker.",292,"2026-02-24T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":20},[83],{"id":16,"name":17,"slug":18,"color":19,"icon":20},"\u002Fblog\u002Fcovers\u002Fcertificats-ssl-lets-encrypt-vps-poster.svg",{"categorySlug":86,"appSlug":87},"securite","certbot",{"id":89,"slug":90,"title":91,"excerpt":92,"readTime":11,"views":12,"isPinned":13,"publishedAt":14,"category":93,"categories":94,"featuredImage":23,"bgImage":24,"posterImage":96,"relatedSolution":23},201,"crawlers-ia-search-training-agent","AI Crawlers: taking back control over your clients' sites","Cloudflare now splits AI crawlers into three families. How to configure robots.txt and Cloudflare rules to protect your clients' sites.",{"id":16,"name":17,"slug":18,"color":19,"icon":20},[95],{"id":16,"name":17,"slug":18,"color":19,"icon":20},"\u002Fblog\u002Fcovers\u002Fcrawlers-ia-search-training-agent-poster.svg",{"id":98,"slug":99,"title":100,"excerpt":101,"readTime":11,"views":12,"isPinned":13,"publishedAt":14,"category":102,"categories":107,"featuredImage":23,"bgImage":24,"posterImage":109,"relatedSolution":23},199,"spf-dkim-dmarc-delivrabilite-emails-pro","SPF, DKIM, DMARC: passing the 5,000-email threshold","Gmail and Outlook reject senders without aligned SPF, DKIM and DMARC with an SMTP 550 error. Here is how to configure all three records.",{"id":103,"name":104,"slug":105,"color":106,"icon":105},11,"Business Email","emails","bg-cyan-500\u002F10 text-cyan-400",[108],{"id":103,"name":104,"slug":105,"color":106,"icon":105},"\u002Fblog\u002Fcovers\u002Fspf-dkim-dmarc-delivrabilite-emails-pro-poster.svg",1785628422503]