After you generate a certificate for a management product in the ROBO that is signed by the certificate authority on the parent AD server in the region, replace the default certificate or an expired certificate with newly-signed one on the product instance in the ROBO.