You need to bind a certificate when you add an HTTPS listener to a load balancer. If the certificate used by a listener has expired or needs to be replaced due to other reasons, you can replace the certificate on the Listeners tab page.
If the certificate is also used by other services such as WAF, replace the certificate on all these services to prevent service unavailability.
Replacing certificates and private keys does not affect your applications.
You have created a certificate by following the instructions in Creating a Certificate.
You can bind certificates when you add an HTTPS listener. For details, see Adding an HTTPS Listener.