Your issuing CA's key expires in a year. In most shops that kicks off a renaming project: ica-tls-2027, new URLs, every template and client updated by hand. goca refuses the premise.
A generation is a CA's key + certificate at one point in its life. Rollover creates generation N+1 under the same logical CA — templates, bindings and clients keep addressing the logical name and never notice. The name is the stable thing; the key material is what ages.
The console leans into this: Configuration → CAs opens on a table of generations, one row per generation, not per CA — because the questions an estate raises are generation questions. Which key is active? Which expires first? Which is still on a software key? (Custody is software) What has ever rolled? (Gen is greater than 1).
Now I can tell a CA from its generation — and say which one clients address.