It puts additional burden upon the IT department to always send a valid certificate. Of course, it should never happen that we send an expired or revoked certificate. But mistakes happen. I'm skeptical.
But we can set the header and then see if there will be any complaints … :-)