If you use a well-known, Internet CA to issue the certificate,
you can handle the certificate renewal in two different ways.
You can renew the certificate directly with the Internet CA and then
import the renewed certificate from the file that you receive from the signing
CA. Or, you can use DCM to create a new public-private key pair and Certificate
Signing Request (CSR) for the certificate and then send this information to
the Internet CA to obtain a new certificate. When you receive that certificate
back from the CA you can then complete the renewal process.