I don't trust the average user to inspect the certificate and understand the reason for the browser's rejection.
Telling people not to worry about expired cert warnings makes them vulnerable to a variety of attacks.
More over, if your org's browser setting allow you to override the warnings, thast also pretty bad for anything other than a small subset of your team.