It does make me wonder if the zealous pursuit of shorter expirations has gone too far, especially up at the root. Is there good public discussion on root expiration? Seems to mostly come up when old devices get bricked because of it. Certainly 15 year expirations are not a substitute for extremely strict root key management or root key revocation.
Haven't seen a specific one but I guess the most relavant public discussion on root CA-led device bricking issues might have occurred around the time when DST Root CA X3 (naturally) expired - that's around September '24: https://letsencrypt.org/2023/07/10/cross-sign-expiration.htm...
I personally believe most issues blocking old device reuse can be solved by manufacturers returning the root permission back to users, so that users can install modded systems with up-to-date stuffs. However, it's a pity that manufacturers aren't willing to do it, as it hurts their interest on selling new devices. Will laws on "right to repair" work? Time will tell.