Why do SSL certificates expire? Seems like a suboptimal design decision.
Furthermore, private keys can be cracked, given enough time. Expiry dates reduce this risk with (a) less time to do it; (b) key is invalidated even if you don't know that it's been compromised, so every compromise ends sooner or later, and (c) renewed certificates can be made with longer keys as hardware gets more powerful.