Glossary / Let's Encrypt
What is Let's Encrypt
Let's Encrypt is a non-profit certificate authority that issues SSL certificates for free and fully automatically. It made HTTPS available to any site without payment or manual hassle. These are the certificates most hosts install by default, including through AutoSSL in cPanel.
Check your site
Instead of manual issuance, Let's Encrypt runs on the ACME protocol: a small program on the server proves the domain is yours, gets the certificate, and installs it. The check happens through a file on the site or a TXT record in DNS.
Let's Encrypt certificates last 90 days, and that is deliberate. The short lifetime pushes you toward auto-renewal, so on a properly set up server the certificate renews itself without your involvement.
Let's Encrypt issues Domain Validation certificates: it confirms control of the domain but does not vet the company. That is enough for a regular site, but there is no extended validation with an organization name here.
Example
Issuer: Let's Encrypt R11 Validity: 90 days
Common mistakes
- Assuming a free certificate means weaker protection. The encryption is the same as paid ones, only the validation level differs.
- Installing the certificate by hand and forgetting renewal, when the whole point of Let's Encrypt is automation.
- Expecting organization validation or money-backed warranties from Let's Encrypt. It only issues domain-level certificates.
- Blocking the /.well-known/acme-challenge path with .htaccess rules, which silently breaks auto-renewal.
Related terms
Found problems?
Slow hosting, SSL trouble or frequent downtime? Move to TomisHost: fast hosting with free SSL, daily backups and free migration help.
TomisHost hosting