Yeah the defaults for cert manager have been adjusted - because quite often these certs are installed on things you would be hitting with a browser.  Say a web gui for pfsense ;)  Or your web server your setting up, or some other gui for other software, or appliances like switches, etc.
But when it comes to your openvpn - this is pretty isolated.  The only thing using these certs are limited to the openvpn server/client.  So the limitations for life of these certs would be controlled by the software and not the OS running the software.