maybe i just dont know how they work. but it was my impression that a verification request is sent to the certificate authority every time a connection is attempted. in that case, the length of the certification validity would be somewhat irrelevant as the validation request would fail because Lets Encrypt was down.