Signature expiration times must be set far enough in the future that it is quite certain that new signatures can be generated before the old ones expire. However, setting expiration too far into the future could, if bad data or signatures were ever generated, mean a long time to flush such badness.
It is recommended that signature lifetime be a small multiple of the TTL but not less than a reasonable re-signing interval.