After the certificate for the NSX principal identity expires, you regenerate and update the certificate. You then replace the certificate and private key and you refresh the credential in VMware Aria Operations.