I'd like to know as well. At my work we had to partner with a major bank and they demanded a fully signed (sigh) client certificate for the integration. The way their API works means that we have to do a planned hard-cutover before the certificate expires. There's a 60% chance that we'll have trouble reaching out to the right people when the time comes.
Ugh.