Unfortunately, this approach (while being quite feasible from the
technical POV) appears to be incompatible with the business model of
existing CAs.
Everyone loves blaming the business guys. Nope. When it comes to X.509,
we nerds blew it.If you have got 500 servers that need renewed certificates
then you have.
...(alot of work ahead of you.)