> I can see the problem and given the fact that the expiration date
> can be changed later, it might make sense to have a default
> expiration time: 6 months, 1 year or 2 years?
1 year is a good default, I feel. This gives new users enough time to understand how OpenPGP systems work, and extend their keys if necessary (even if only through creating a new key, signed by the old one).