the PKI on the firewall is not meant as a company wide certificate authority. The intention is to use it for X.509 based vpn user authentication. So there is no need to configure the expire date. Issue a new certificate after a year and replace the old one in the vpn connection and/or simply delete it.