The Let’s Encrypt community-driven nonprofit certificate authority, which provides free certificates to anyone who wants them, has begun issuing free certificates for IP addresses and has also introduced the option of obtaining TLS certificates with a lifespan limited to 160 hours (6 days). On May 13, they plan to add support for optional issuance of certificates valid for 45 days. According to the previously announced plan, by February 10, 2027, the maximum validity period of certificates will be reduced from 90 to 64 days, and on February 16, 2028, it will be further reduced to 45 days.
The certificates for IP addresses available starting today are issued for 6 days and allow secure encrypted access to hosts not only when using domain names but also when accessing directly via IP address. Secure access to the web server via IP address can be useful when interacting with home devices; during the initial setup or testing of new servers; for organizing encrypted connections between backends in the internal infrastructure; for creating placeholder pages displayed when accessing via IP; when deploying personal servers; and for accessing DoH (DNS over HTTPS) servers directly via IP.
Certificates for domains, with a validity limited to 6 days, can be used to enhance the security of infrastructure — in the event of an unnoticed certificate leak due to a breach, short-lived certificates will prevent attackers from controlling the victim's traffic for an extended period or using the certificates for phishing.
To request a short-lived certificate for a domain and a certificate for an IP address, the ACME client must support an extension of the protocol that implements profiles, as well as support for the 'shortlived' profile. Only the http-01 and tls-alpn-01 methods can be used to verify ownership of the IP address (the dns-01 method is prohibited).
Source: opennet.ru
