> since you would need to ask for the certificate from a central authority
Could it work that your long-term certificate (90 days, whatever) gives you the ability to sign ephemeral certificates (much like, e.g. LetsEncrypt signs your 90 day certificate)? That saves calling out to a central authority for each request.
> Perhaps it's time to go with another method entirely.
What method would you suggest here?