Microsoft will do this at it's own convinience sometimes after reaching 80% of it's life time. Preferably friday evening so it will take the longest time to get "resolved".
We have several customer that align with us to do this on a scheduled maintenance window for this particular activity. (Usually right after lunch.)
But the akward thing is that there is now design to validate new certificates based on their CA inside Check Point. Like someone still klings to the old putkey methods for this particular feature and CA's are not to be trusted.
<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>