To care about stale certs on snapshots or the opposite?

Both. One breaks your restore, the other breaks your trust chain.