Re: "How is automatic renewal a pain?"
"Try it on some network and embedded devices, where renewing certificates has to be done manually and it's a quite slow process."
So, shouldn't you first be taking that out on the network and embedded device manufacturers for not providing a way of automating it?
(PS: I sympathise though - same boat :-(