If the lifetime of an issuing or sub CA is twice the lifetime of the end entity certificates issued by it and the renewal cycle of the issuing CAs is a little shorter than the validity of the end entity certificates then three generations of CA certificates have to be handled by the cert-enroll scripts.