@lamp certs with shorter lifetimes are more secure because it reduces the impact of the private key is leaked/exposed/stolen by rotating it. With a cert with a long lifetime, the attacker can impersonate your site for as long as the cert remains valid. That's why let's encrypt certs are only 90 days instead of what was previously the industry standard of 5 years, it greatly lessens the impact of an exposure/leak.