I doubt google has certificates that run out automatically. Rather, the best way is with each signing to include signing the date and not allow the certificate to expire retroactively.
Is it really necessary? Aren't there other possible ways of invalidating a certificate other than its date?