# letsencrypt.org > AI-optimized mirror of letsencrypt.org containing 24 pages totalling 15,131 words of clean markdown content, structured data, and semantic HTML. Original source: https://letsencrypt.org/. Last updated: 2026-06-15T21:31:30.003Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [Encryption for Everybody](/content/site-root.html): Let's Encrypt is a free, automated, and open Certificate Authority brought to you by the nonprofit Internet Security Research Group (ISRG). Read all about our nonprofit work this year in our 2025 Annual Report. , (483 words) ## Articles & Blog Posts - [blog/index.html](/content/blog/index.html) (1 words) - [documents/isrg-cp-cps-v5-7.html](/content/documents/isrg-cp-cps-v5-7.html) (1 words) - [FAQ](/content/docs/faq/index.html): This FAQ is divided into the following sections: General Questions Technical Questions General Questions What services does Let’s Encrypt offer? Let’s Encrypt is a global Certificate Authority (CA). We let people and organizations around the world obtain, renew, and manage SSL/TLS certificates. Our certificates can be used by websites to enable secure HTTPS connections. Let’s Encrypt offers Domain Validation (DV) certificates. We do not offer Organization Validation (OV) or Extended Validation (EV) primarily because we cannot automate issuance for those types of certificates. , (1,050 words) - [Revocar un certificado](/content/es/docs/revoking/index.html): Cuando la clave privada correspondiente de un certificado ya no es segura, debe revocar el certificado. Esto puede suceder por diferentes razones. Por ejemplo, podría compartir accidentalmente la clave privada en un sitio web público, los piratas informáticos pueden copiar la clave privada de sus servidores o los piratas informáticos pueden tomar el control temporal de sus servidores o su configuración de DNS y usarlo para validar y emitir un certificado para el que poseen la clave privada. , (689 words) - [Six-Day and IP Address Certificates Available in Certbot](/content/2026/03/11/shorter-certs-certbot/index.html): This was also posted on EFF’s blog. As we announced earlier this year, Let’s Encrypt now issues IP address and six-day certificates to the general public. The Certbot team at the Electronic Frontier Foundation has been working on two improvements to support these features: the --preferred-profile flag released last year in Certbot 4.0, and the --ip-address flag, new in Certbot 5.3. With these improvements together, you can now use Certbot to get those IP address certificates! , (535 words) - [Ending OCSP Support in 2025](/content/2024/12/05/ending-ocsp/index.html): Earlier this year we announced our intent to provide certificate revocation information exclusively via Certificate Revocation Lists (CRLs), ending support for providing certificate revocation information via the Online Certificate Status Protocol (OCSP). Today we are providing a timeline for ending OCSP services: January 30, 2025 OCSP Must-Staple requests will fail, unless the requesting account has previously issued a certificate containing the OCSP Must Staple extension May 7, 2025 Prior to this date we will have added CRL URLs to certificates On this date we will drop OCSP URLs from certificates On this date all requests including the OCSP Must Staple extension will fail August 6, 2025 On this date we will turn off our OCSP responders Additionally, a very small percentage of our subscribers request certificates with the OCSP Must Staple Extension. If you have manually configured your ACME client to request that extension, action is required before May 7. See “Must Staple” below for details. , (752 words) - [Intent to End OCSP Service](/content/2024/07/23/replacing-ocsp-with-crls/index.html): Today we are announcing our intent to end Online Certificate Status Protocol (OCSP) support in favor of Certificate Revocation Lists (CRLs) as soon as possible. OCSP and CRLs are both mechanisms by which CAs can communicate certificate revocation information, but CRLs have significant advantages over OCSP. Let’s Encrypt has been providing an OCSP responder since our launch nearly ten years ago. We added support for CRLs in 2022. Websites and people who visit them will not be affected by this change, but some non-browser software might be. , (487 words) - [6-day and IP Address Certificates are Generally Available](/content/2026/01/15/6day-and-ip-general-availability/index.html): Update: March 11, 2026 If you use Certbot, see Six-Day and IP Address Certificates Available in Certbot for details on requesting these certificates. Short-lived and IP address certificates are now generally available from Let’s Encrypt. These certificates are valid for 160 hours, just over six days. In order to get a short-lived certificate subscribers simply need to select the ‘shortlived’ certificate profile in their ACME client. Short-lived certificates improve security by requiring more frequent validation and reducing reliance on unreliable revocation mechanisms. If a certificate’s private key is exposed or compromised, revocation has historically been the way to mitigate damage prior to the certificate’s expiration. Unfortunately, revocation is an unreliable system so many relying parties continue to be vulnerable until the certificate expires, a period as long as 90 days. With short-lived certificates that vulnerability window is greatly reduced. , (404 words) - [OCSP Service Has Reached End of Life](/content/2025/08/06/ocsp-service-has-reached-end-of-life/index.html): Today we turned off our Online Certificate Status Protocol (OCSP) service, as announced in December of last year. We stopped including OCSP URLs in our certificates more than 90 days ago, so all Let’s Encrypt certificates that contained OCSP URLs have now expired. Going forward, we will publish revocation information exclusively via Certificate Revocation Lists (CRLs). We ended support for OCSP primarily because it represents a considerable risk to privacy on the Internet. When someone visits a website using a browser or other software that checks for certificate revocation via OCSP, the Certificate Authority (CA) operating the OCSP responder immediately becomes aware of which website is being visited from that visitor’s particular IP address. Even when a CA intentionally does not retain this information, as is the case with Let’s Encrypt, it could accidentally be retained or CAs could be legally compelled to collect it. CRLs do not have this issue. , (347 words) - [ISRG CP/CPS v6.1](/content/documents/isrg-cp-cps-v6-1.html): ISRG CP/CPS v6.1 (10,369 words) - [documents/isrg-cp-v1-3-pdf.html](/content/documents/isrg-cp-v1-3-pdf.html) (1 words) - [tr/sitemap-xml.html](/content/tr/sitemap-xml.html) (1 words) - [ko/sitemap-xml.html](/content/ko/sitemap-xml.html) (1 words) - [cs/sitemap-xml.html](/content/cs/sitemap-xml.html) (1 words) - [si/sitemap-xml.html](/content/si/sitemap-xml.html) (1 words) - [ca/sitemap-xml.html](/content/ca/sitemap-xml.html) (1 words) - [el/sitemap-xml.html](/content/el/sitemap-xml.html) (1 words) - [fr/sitemap-xml.html](/content/fr/sitemap-xml.html) (1 words) - [ru/sitemap-xml.html](/content/ru/sitemap-xml.html) (1 words) - [sitemap-xml.html](/content/sitemap-xml.html) (1 words) - [de/sitemap-xml.html](/content/de/sitemap-xml.html) (1 words) - [pl/sitemap-xml.html](/content/pl/sitemap-xml.html) (1 words) - [hu/sitemap-xml.html](/content/hu/sitemap-xml.html) (1 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/content/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives