If you are using the default self signed certificate it should automatically update every time you patch the server.
Or you can renew it by creating a new self signed certificate, click the Create Self-Signed Certificate link in the top right of Certificate Store
Fill in the form, all fields can be blank except the SAN field that is required to have a name DNS:<MGMT IP>

If you have a certificate from a CA, just create a CSR from the other link, remember the SAN field with DNS:<MGMT IP>
Send the CSR to the CA admin, and when the certificate is returned, import the certificate.
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------