Can someone explain what the business reason for backdating certs is? I understand it was to get around the notAfter but I don't understand who gains from this? Is it just old code they are too cheap/lazy to update?
To create SHA-1 certificates for compatibility with older software. SHA-1 certificates may not be issued after December 31, 2015 and in any case browsers will not trust them. They created new certificates in 2016, with a "Start Date" in 2015 so that they satisfied this rule. This is forbidden for two reasons, first you cannot "back date" certificates and second you are no longer allowed to issue SHA-1 certificates, so they back dated to work around this.
Yeah old java6 TLS stacks have problems with SHA256, amoung other legacy systems used by the old guard