You need to generate new certificate to replace expired one on each Exchange server and domain controller.
To get more details please read the following links:
Assign certificates to Exchange Server services
Enable LDAP over SSL with a third-party certification authority
Please don't forget to accept helpful answer