"I for one do NOT see this as being reasonable"
I entirely agree. All this "enforced security" by browser vendors has done so far is to spawn a massive increase in use of unverifiable cheap self-signed certificates that consequently validate nothing. I strongly suspect that it's primarily another attempt at enforced churn rather than a genuine concern for our security.