Your arguments is that one website out of four wouldn't be able to talk with a client only supporting PFS. It have been said that a lot of these bad apple are bank server, those who are not going to upgrade anytime soon.
If you need PFS only, go ahead. I'm pretty sure it's only a matter of changing a pair of compile flag on libreSSL. But please, pretty please, let the dev doing there job. And drop these caps, you're looking silly.