The Glassfish distribution contains a template truststore that was created from that of the JDK.
When a domain is created, the template is used to create the truststore of the domain. You can correct an existing domain by removing the expired cert from its truststore, and you can correct the template to prevent the certificate from being reintroduced in future domains.
[Message sent by forum member 'monzillo' (ronald.monzillo_at_sun.com)]