I don't understand #1 - what prevents you from doing this today? When you generate a certificate you get to pick the expiration date; you are free to make it as short as you want. Don't intermediate certificates exist to implement this strategy?
And who is going to issue you a reasonably-priced intermediate cert? Especially since PKIX name constraints don't actually work, so that intermediate cert would let you sign just about anything.
edit: basically, what stops you from doing this?
Root CA root cert (20y expiration)
v
Root CA intermediate cert (10y expiration)
v
Your intermediate cert (1y expiration)
v
Your short-lived cert (24h expiration)