Hello Jerome,
very good question :-) Unfortunately I can't provide an answer, so I'd suggest to open ticket with Customer Care.
Maybe worth to know: when a Genesys certificate is about to expire, a new certificate is created some months (3?) in advance. This is then used by new instances of the service which performs the data actions - but already running instances still use the old certificate. That's one of the reasons your service should trust the root CA, and not the leaf certificates...
------------------------------
Christian Karpp
Principal PS Consultant
------------------------------