Sign me as an Intermediate CA for my Domain with Name Constraint?

Great conversation all around here. You’ve hit the main points - under current BRs, a name constrained subordinate has to meet all the same requirements an unconstrained subordinate does, which means secured storage and audits. It would be quite a lot of work and expense!

However, I agree that in a future world with better support for name constraints, it might make sense for the BRs to be amended to lower the bar for name constrained subordinates.