The situation we found ourselves in is simple: institutions were systematically unable to quickly rotate certificates when they were compromised.
Precisely because of busywork and process fragility that they invented, with a strictly negative benefit for security and end-users.
Can you propose another path to address this issue?