Is there any downside or up to importing the local certificates from the primary as opposed to configuring the local certificates manually on the new secondaries?
"New local certificates—You can either configure the local certificates on the secondary servers or import the local certificates from the primary server."
http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-8/installation/guide/csacs_book/csacs_deploy.html