You shouldn't consider the certificates and corresponding private keys "configuration", but rather volatile host-specific variables.
Your setup will be both simpler and more resilient (no inter-dependencies) if both MX'es have their own certificates.