Hi,
The default validity for a user certificate generated from a ASA as a CA server is one year (by default). But while generating the certificate from the ASA, you can change the user certificate vaildity to more than one year. Following link provides you with the procedure:
http://www.cisco.com/en/US/docs/security/asdm/6_2/user/guide/certs.html#wp1357943
Let me know if this helps,
Cheers,
Rudresh V