The upgrade routine should check for expired certificates as STEP 1 in the upgrade process. This should be a Prerequisites checklist type of upgrade routine. If any of the prerequisites do not pass, do not even continue the upgrade. Then inform the user that these items need to be resolved first before the upgrade can commence. If the eDir CA Cert is expired, tell us so we can get it fixed.
Today it does not do this check, so when the upgrade is all done to SLES 11 SP3 + OES 2015, many of the OES services (i.e. novell-nss, etc) do not start up since the CA Certificate was expired.