I did some testing and yes if you reinstall a host and don't perform puppet 
cert clean on all the ca servers you will run into issue.  But other than 
this fact I haven't seen any issues with masters verifying a signed 
certificate.  Since running puppet cert clean is standard procedure I don't 
see this as a complicated task to distribute when re-provisioning .

