Like you mentioned , the certificates that allows clients which are MA managed, are exchanged between the connected ePO servers.
Regarding the Open CA, since there is currently no easy ways for admins to see open clients especially from other ePO servers. So this was intentionally not exchanged.
When you import the certificate, it is visible in the UI and the admin is aware.
If you see a use case where this will be needed in a production environment , we can consider ways to make this easier.