This is going to be one of the obvious traps.

To care about stale certs on snapshots or the opposite?

Both. One breaks your restore, the other breaks your trust chain.