vCert.py script from KB 385107 was successfully run to replace all certificates. However, the dates of the certificates did not change.
A certificate's validity period cannot exceed that of the certificate authority (CA) that issued it. Specifically, the VMCA cannot sign certificates with a longer lifetime than its own. Once the root CA's validity expires, it loses the trust required to sign new certificates, and any certificates it previously signed may consequently become untrustworthy.