We currently use tasks/check-certs/check-certs.rb in the cf-deployment pipeline to make sure that the certs used in our environments won't expire soon. However, at the moment the task only checks certain bbl-generated yaml files.
Almost all of our environments maintain separate, and currently unchecked, LB certs. Many of them are now located in lb-certs directories alongside the relevant bbl-state directories in relint-envs. Some are still located in credhub for those environments.