Just replacing unused/expired certificates probably won't be much use by itself. A bitmask is used to select which certificates will be loaded, the expired ones will not be included in the bitmask used by libssl or vsh.
Oh and the MD5 hashes of the certificate files are checked against...