Right. But if you’re trying to establish an HTTPS connection to some server then that server’s cert is signed by some trusted root and THAT cert expires.
Which is why it might be more future proof to embed your own non expiring cert and use an out-of-band signature verification for firmware rather than relying on being able to establish an HTTPS connection forever.