I just hope that automation doesn't bring new vulnerabilities... Otherwise we get safer cert but poorly secured automated PKI to create the certs?
I mean if you have a fully automated cert deployment it could be months with a compromised system and you probably wouldn't see it.
I don't know how effective this will be. It still seems short even if it starts in 2029.