You need to bind a certificate when you add an HTTPS listener to a load balancer. If the certificate used by the load balancer has expired or needs to be replaced due to other reasons, you can replace the certificate.
If the certificate is also used by other services such as WAF, replace the certificate on all these services to prevent service unavailability.
Replacing certificates and private keys does not affect your applications.
You have created a certificate by following the instructions in Creating a Certificate.
You can bind certificates when you add an HTTPS listener. For details, see Adding an HTTPS Listener.