I think it's a bit LE specific here though, since according to the article, real trust anchors do not expire on android, so it's only because LE is relatively new and was not a bundled CA root at the time, and had to be signed by a CA that was bundled (and this intermediate signature is what expires if I understand correctly)