The update of the eap-tls certs to be done on the voice server on the corresponding badges eap-tls folder to avoid any connectivity issues once the certs have expired , this would allow the badges to have the new certs before hand once they establish connectivity to the network and it would have the updated certificates.
To give more brief, we can import the cert chain onto the eap-tls folder of the badge bedofe updating the cert on the ISE or NPS server so the badges would have the valid certificate beforehand rather than goign through the eap-tls transaction and this sometimes fails becasue of the cert validity.
This would be related to https://vocera.aha.io/features/BCU-5
We need a bit more elaboration on the use of a certificate chain and the problem being solved before we can scope it or consider promotion to an idea