How does expiration work? What happens if an TLS/SSL cert is leaked/compromised? Change the clients as well?
But yeah, if they're leaked you just gotta re-send them to the clients. This isn't meant for large professional projects, only for stuff where the convenience outweights the pros of using a proper certificate.