Update on TLS Certificates
To improve the security of TLS certificates, the CA/Browser Forum decided in 2025 to gradually reduce the maximum validity period of certificates from the previous 398 days to 47 days. We already outlined the timeline in our blog post at the time: https://www.iacbox.com/en/blog/tls-certificates-validity-periods-to-be-reduced/
Since March 15, 2026, certificates may be valid for a maximum of 200 days. From March 2027, the limit will be reduced to 100 days, and from March 2029 to just 47 days.
We will therefore switch to Let’s Encrypt certificates in the first quarter of 2027. Since the certificate for our default domain, hotspot.internet-for-guests.com, expires in November 2026, IACBOX update 24.3.6 will include one final certificate with a 200-day validity period, valid until April 2027. This gives us plenty of time for a smooth transition. As an IACBOX operator, however, you won’t notice any difference.
Certificates Independent of Software Updates
Until now, TLS certificates have been distributed with software updates. The certificate included in version 24.3.6 will be the last one delivered this way. The short-lived Let’s Encrypt certificates, on the other hand, will be distributed independently of software updates, similar to our DNS filter lists.
The required infrastructure has already been part of IACBOX for several months. Going forward, IACBOX systems with valid Software Maintenance will therefore always receive an up-to-date TLS certificate, regardless of the installed software version. To avoid issues in case Software Maintenance is renewed late, there will also be a grace period of several weeks.
Technical Implications
As a captive portal, we need to take a conservative approach when choosing a root CA (Certificate Authority), as we want even relatively old devices to trust the certificate issuer.
Let’s Encrypt’s root CA, ISRG Root X1, was created in 2015 and has been included in all major operating systems and browsers since around 2016–2018. It is therefore widely supported today. Older devices were previously supported through a cross-signature from an older CA. When that certificate expired in 2021, some older devices experienced compatibility issues.
We are also switching from RSA to EC (Elliptic Curve) certificates. EC certificates have been widely supported for many years, are significantly smaller, and therefore help speed up connection establishment.
White-Label Partners
For our whitelabel partners, we will take care of issuing and distributing partner certificates in the future. All we need is an additional DNS record that delegates domain validation for Let’s Encrypt to us.
We will contact our whitelabel partners about this in the coming months.
Custom Domains
Since version 24.3.0, you have been able to upload TLS certificates for your own domain via the Admin API (formerly the Batch API). This allows IACBOX to integrate seamlessly into your automated environment.
You can find the API documentation here:
https://manual.iacbox.com/admin-api/24/
A ready-to-use upload shell script is also available here:
https://manual.iacbox.com/iacbox/24.0/docs/interfacing/admin-api/#api-helper-scripts
The script can be used as a deploy hook for certbot and virtually any other ACME client.
Outlook: Post-Quantum Cryptography
The move to 47-day certificates won’t be the end of the story. Merkle Tree Certificates (MTCs) are already on the horizon. They are intended to make signature schemes that can withstand quantum computers practical for use on the web, as their signatures are significantly larger than those used today.
MTCs are expected to have validity periods of only a few days and are anticipated to be supported by Google starting in late 2027.
By 2027 at the latest, automated certificate management will become the norm.
Stay secure and up to date with IACBOX Software Maintenance.