You still state in your updated post that: "The surprising aspect is that Authz has a validity of 300 days (which is likely to be increased)" [emphasis mine]. This would appear to be incorrect based on the source cited above , where it is stated at "Eventually, we'd like to make authorization objects much shorter than certificate lifetimes, probably 7 days."
Perhaps it's worth updating the post again in light of this?