points
It is the user machine that needs new certificate signed by the CA once the short-lived one expires.
Ahh, now you have three problems…hrm