check this on the CA:
certutil -getreg ca\ValidityPeriodUnits
certutil -getreg ca\RenewalValidityPeriodUnits
Also, check the validity period defined in the certificate template.
Lastly, if the CA cert has been around for awhile, it may be truncating the issued certs - an issued cert cannot be valid for longer than the validity period of the CA cert. 2 years for an issued cert is actually common from a CA with a validity of 5 years, or 3 years from a 6 year CA cert (the half-life, rounded down)