Its more about the actual CRLs and the distribution point for those certs. FAS doesn't need that issuing CA up once it has a certificate from it and that said cert is not expired. BUT whatever you are using for the CRLs and checking those certs all the way up the chain better be available and accessible. Sometimes its good to stagger the FAS servers pulling their auth cert a day apart or something so the expiration isn't on the same day.