When an app is signed with a certificate that has expired, the more information dialog (attached) has a link to java.com that opens a page related to apps with self-signed certificates. This should be removed for this case.
See this test case:
http://javasec.us.oracle.com/mullan/public_html/tests/PluginSignedApplets/signed-expired-timestampedAfterExpiration.html
See this test case:
http://javasec.us.oracle.com/mullan/public_html/tests/PluginSignedApplets/signed-expired-timestampedAfterExpiration.html