Customer has an on-premises RDS farm (three RDS servers and a separate server acting as gateway/connection broker). All Windows Server 2019.
The GoDaddy SSL Certificate is expiring soon, so I'm reviewing their environment to determine the next steps.
The current certificate is assigned and bound in IIS, but when looking in Server Manager > Remote Desktop Services > Collections > Tasks > Deployment Properties > Certificates I see the Role Services are not using the new certificate. They are still all using a certificate that expired in 2022.
Employee's remote in from both on their network and off their network (no VPN) using an RDS shortcut.
Their RDS web page (https://workdesk.CENSORED.com/RDweb) is using the current (soon to expire) certificate and working properly.

Using the "Select existing certificate" option, I am unable to assign a current certificate to these Role Services because it requires a PFX file type (no option to change it in drop down).
Questions
A) How are their employee's able to remote into the RDS environment with those Role Services using an expired certificate? None of them recall getting the gold banner security warning when connecting.
B) What is the proper way to renew a third party issued SSL Certificate for an RDS farm like this? I was unable able to find an official Microsoft guide. Should we be using the "Create new certificate" from the Deployment Properties to generate a CSR, rekey the cert with GoDaddy, then come back and install the cert in Deployment Properties and IIS? Seems like last year someone just renewed the cert in GoDaddy, then installed it in IIS on the GW/CB. I want to ensure we are getting the new certificate installed properly.
Thank you for your time to read through my post and contemplating this issue.