Anyone using email validation now needs to click a link every month, or their cert goes away.
I used to have the unfortunate task of managing a massive SAN cert used for white-label hosting with a bunch of our customer's domains.
Getting every single customer to get their tech person to look at the mailbox and click a link was often a multi-month process.
If you're in a position to MITM using a stolen certificate, you're probably also in a position to block the CRL response from going through. Since failing to get an updated CRL doesn't result in a security warning, your CRL proposal is essentially useless.
Not if the certificate is OCSP-Must-Staple.
Short cert lives make certain decloaking much, kuch more difficult.
It seems like driving this number up is a better way of dealing with historic traffic than quickly expiring certs. Limiting the duration of leaks of future traffic seems like the right justification for short lived certs.
That recent GnuTLS bug resulted in bad guys not even needing to steal that resumption key for any servers using affected versions of GnuTLS because GnuTLS was just initialising it to zero...
Digicert is in the process of migrating their customers to ACME (the issuance protocol used by Let's Encrypt and certbot). Where's your god now? :)
I can forsee the browsers eventually treating self-created CAs like they currently treat self-signed certs. if they're not traceable to a trusted root CA then there's no accountability, from a browser perspective, in the event of abuse or breach.
Without centralization I can MITM at the coffee shop and steal passwords.