Would be nice if TLS supported:
1) "hot" certificates with 24h ttl signed-off by a longer-living certificate on a more secure machine. Having 1-year certificate private key deployed on a web server is crazy. Especially since revocation does not really work.
2) Threshold multi-signature certificates for both CAs and end-user certificates.
3) CA certificates locked to specific TLDs (was there RFC about something like that already?) - so Russian CA cannot sign certificate for a Canadian TLD.
4) Ultimately, blockchain name pinning on DNS level.
The last three do not really relate to a case when bug in OpenSSL reveals a private key stored on web server.