There are multiple way to renew Cloud Connector UI and System Certificate. The Option i used multiple that is "Create and import a self-signed certificate" apart from this we can import certificate as shown in below snap.
To do so from the left panel, choose Configuration. On the tab On Premise, choose System Certificate Import a certificate to upload a certificate and provide its password: its simple and easy way to renew Cert.
A second option is to start a certificate signing request procedure as described for the UI certificate in Exchange UI Certificates in the Administration UI and upload the resulting signed certificate.
If having intermediate certificates in place, make sure you import the complete chain (for example, as PKCS#7 file) so that mTLS connections always work properly.
You can verify this in the Certificate Chain area of the System Certificate section:
third option is to generate a self-signed certificate. It might be useful if no CA is needed, for example, in a demo setup or if you want to use a dedicated CA. For this option, choose Create and import a self-signed certificate:
If a system certificate has been imported successfully, its distinguished name, the name of the issuer, and the validity dates are displayed:
Regards
Rupesh Shankar Chavan